Public phishing feed: suspicious/confirmed phishing URLs detected hourly. No auth, CC0.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Phishunt.
check_domainIs this host (or a list of up to 20) in the active phishunt feed? Exact match; misses are checked against the archive.
list_brand_phishingsList active phishings targeting a brand (e.g. `microsoft`).
get_recent_detectionsDelta sync: detections since an ISO date.
get_brand_metadataCurated brand metadata (display name, category, AI characterisation, active count).
get_cert_metadataFactual metadata for an abused TLS intermediate CA (operator, root, key type, siblings).
search_phishingsFree-text search across active phishing URLs/domains/IPs (min 3 chars).
Model Context Protocol (MCP) server for phishunt.io.
Exposes the public phishing-domains feed as MCP tools so AI agents can look up suspicious domains, list phishings by targeted brand, and sync detection deltas.
https://mcp.phishunt.io/ (HTTP JSON-RPC 2.0, POST)| Name | Purpose |
|---|---|
check_domain | Is this host (or a list of up to 20) in the active phishunt feed? Exact match; misses are checked against the archive. |
list_brand_phishings | List active phishings targeting a brand (e.g. microsoft). |
get_recent_detections | Delta sync: detections since an ISO date. |
get_brand_metadata | Curated brand metadata (display name, category, AI characterisation, active count). |
get_cert_metadata | Factual metadata for an abused TLS intermediate CA (operator, root, key type, siblings). |
search_phishings | Free-text search across active phishing URLs/domains/IPs (min 3 chars). |
analyze_url | Passive phishing-signal analysis of any URL/domain - returns a single adjudicated verdict (phishing / likely_phishing / suspicious / no_evidence / not_assessed) plus the supporting evidence (URL-shape heuristics, stored score/verdict if known, external-feed cross-reference, historical detections). Unknown suspicious domains are auto-queued for full analysis. |
analyze_url_deep | ACTIVE deep analysis of a URL (contacts the target: HTTP + TLS cert + RDAP + NS + GeoIP, SOCKS5-isolated) and re-scores it with the full 5-layer engine. Slow (5-15s), token-gated, and rate-limited (shared 50/day budget, single-flight) β requires DEEP_TOKEN configured on this Worker; use only when analyze_url is inconclusive. |
get_related_infrastructure | Find infrastructure/content overlap for a known indicator (shared IP, cert, nameservers, favicon, etc.); surfaces the possible campaign / suspected cluster it belongs to. |
get_campaigns | List possible campaigns / suspected clusters (shared-infrastructure groupings), optionally filtered by brand or active-only. |
get_campaign | Full detail for one possible campaign / suspected cluster: evidence breakdown, every member indicator, export links. |
Add to your MCP client config:
analyze_url_deep needs a DEEP_TOKEN Worker secret (the backend's
X-Phishunt-Deep-Token). Without it configured, the tool still appears in
tools/list but fails clean on tools/call β it never reaches the backend.
Factual signals from GitHub, npm, and our automated checks β not a rating.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/phishunt)<a href="https://allmcps.com/mcp/phishunt"><img src="https://allmcps.com/api/badge/phishunt?style=directory" alt="Phishunt on AllMCPs" /></a>