PhishEye

C
C tier on Digital Risk Protection SoftwareScore 6.9 · #1 of 26
Android app
Not listed
Free plan
Yes
Runs on
api, Web
phisheye.com
The PhishEye homepage

Summary

PhishEye detects phishing, typosquat and lookalike domains, brand abuse, and impersonation, and supports takedown workflows. It combines domain, DNS, certificate, hosting, redirect, and live-page signals to identify active brand impersonation. Monitoring covers domains, social channels, ads, search, and app stores. The Free plan offers a single-run typosquat scan for one brand, with 30-day scan history and no takedown cases or requests. Paid plans list automated takedowns through GoDaddy and Cloudflare abuse APIs, though PhishEye does not guarantee that third parties will accept reports or act within a timeframe. Pro lists nine SIEM/SOAR connectors, and plans include STIX 2.1 / TAXII 2.1 threat-feed export. API access is available, and the service is offered on web and API. PhishEye says it builds for security, fraud, and brand teams; plans also include child workspaces for MSP mode. The company describes TLS 1.2 or higher for web and API connections, encryption at rest for supported primary data stores, and MFA for administrative and production-facing accounts. Formal certifications may be pursued as demand and company scale require.

Who it is for

PhishEye suits security, fraud, and brand teams monitoring for impersonation and coordinating takedowns. Plans with child workspaces may also suit MSPs.

What is good

  • Monitors domains, social, ads, search, and app stores.
  • Combines multiple signals to identify active impersonation.
  • Plans include STIX 2.1 / TAXII 2.1 export.
  • Pro lists nine SIEM/SOAR connectors.
  • API access is available.

What to know first

  • Free includes only one single-run typosquat scan.
  • Free has no takedown cases or requests.
  • Third parties may not accept or act on takedown reports.
  • Formal certifications may be pursued, not stated as held.

Everything Xiaomi review

PhishEye: the full review

PhishEye brings brand impersonation monitoring and takedown workflows together, with a limited single-run free scan. Consider the third-party takedown caveat and the certification status when assessing fit.

PhishEye is a web and API service for tracking phishing, lookalike domains and other forms of brand impersonation, with workflows for takedown requests. It is best suited to security, fraud and brand teams, including MSPs that need to separate client workspaces. The free plan is a one-off scan rather than ongoing protection, so its value depends on whether a paid tier fits your monitoring needs.

Overview

PhishEye brings detection and response into one service: it looks for brand abuse across several channels and provides workflows for pursuing takedowns. That combination is useful for teams that want to move from identifying a threat to handling a response without treating domain alerts as the whole job. The free plan is tightly capped, however, and the paid plans' case limits and workspace allowances matter for organizations monitoring multiple brands or clients.

Key features

Detection combines domain, DNS, certificate, hosting, redirect and live-page signals. This gives investigators more context for identifying active impersonation than a domain-name check alone. Monitoring spans domains, social, ads, search and app stores, with dark web monitoring, credential leak alerts and impersonation monitoring also included as capabilities.

Paid plans offer automated takedowns through GoDaddy and Cloudflare abuse APIs. These workflows provide a route to submit reports, not control over the outcome: the providers may decline reports or take an unspecified amount of time to act. Plans also include STIX 2.1 / TAXII 2.1 threat-feed export. Pro adds nine SIEM/SOAR connectors—Slack, Teams, Splunk, Sumo, Sentinel, Defender, ThreatConnect, Tines and XSOAR—which makes it a more relevant option for teams that need to route information into existing security operations.

PhishEye says web and API connections use TLS 1.2 or higher, supported primary data stores are encrypted at rest, and administrative and production-facing accounts require MFA. Its trust page says formal certifications such as SOC 2 Type II or ISO 27001 may be pursued as customer demand and company scale require. Organizations that require one of those certifications should weigh that status before choosing the service. Support is intended to keep the service available during UK business hours; Pro includes priority email support, while Business adds dedicated support and an SLA.

Pricing

The pricing model is free, with a free plan and a 14-day trial. The free tier costs 0.00 USD per free and covers one monitored brand, one single-run typosquat scan and 30-day scan history, with no takedown cases or requests. It is suitable for a basic initial check, not continuing monitoring or incident response.

Starter has custom pricing and includes one monitored brand, daily typosquat scans, 10 takedown cases and 60-day scan history. It suits a team that wants recurring scans and a defined, modest response allowance without needing multiple brands.

Pro also has custom pricing. It expands coverage to three monitored brands and 50 takedown cases, keeps 90 days of scan history, and allows up to five child workspaces and five team members. Its connectors make it the stronger fit for teams integrating the service into security operations, while the workspace and seat caps constrain larger teams.

Business has custom pricing and includes 10 monitored brands, unlimited takedown cases, one year of scan history, up to 25 child workspaces, dedicated support and an SLA. It is the clearest fit for an MSP or organization managing more clients and a sustained case volume. The plans do not provide a published price comparison, so buyers should weigh those capacity differences against a quote.

Platforms

PhishEye is available through web and API platforms. The API option and Pro connectors suit teams that need to integrate monitoring into existing workflows; web access provides the direct service interface.

Who it's for

Security, fraud and brand teams looking for cross-channel impersonation monitoring with takedown workflows are the natural audience. MSPs may find the child workspaces useful for separating client environments, particularly on Pro and Business. A reader who needs a free, ongoing monitoring service or requires established formal certification should look elsewhere; the free plan is a single scan, and formal certifications are not presented as current controls.

Pros and cons

Pros

  • Multiple technical signals and monitoring channels support investigation beyond suspicious domains alone.
  • Paid-plan takedown workflows and threat-feed export connect detection to response and downstream use.
  • Pro connectors and Business workspaces address integration and MSP needs, with capacity increasing by tier.

Cons

  • The free plan allows only one single-run scan on one brand and excludes takedown requests, so it cannot serve as ongoing protection.
  • All paid plans use custom pricing, making cost comparison dependent on obtaining a quote.
  • Takedown providers are not guaranteed to accept reports or act within a timeframe, and formal certifications may be pursued later rather than being a current commitment.

Alternatives

Digital Risk Protection Software and Dark Web Monitoring Services are category starting points for comparing options.

Choose SOCRadar Extended Threat Intelligence Platform if its freemium offer or published monthly Advanced Dark Web Monitoring plans suit your budget: Essential is 600.00 USD per month, billed monthly, for one domain and one seat; Business is 1145.00 USD per month, billed monthly.

Allure Brand Protection is worth considering when flat-rate pricing without per-incident fees or takedown limits is a priority; coverage varies by plan and organization needs.

Flare may fit readers who want to assess a service through a 14-day free trial with no payment information required, though it requires an identity verification call and is scoped to the reader's domain.

ZeroFox Attack Surface Intelligence is another paid option with tailored packages by quote.

Constella Hunter+ is another paid API and web option, with pricing available by demo request.

Fortra Data Security Posture Management may suit mid-sized or evolving security environments that need self-hosted access; its Advanced plan has custom pricing and requires Quick Start Implementation.

Group-IB Attack Surface Management is an alternative with a free trial and pricing based on confirmed external assets, or third-party risk assets for its 3rd Party Risk plan.

KELA Platform offers a 30-day free trial without commitment or payment details, and a Cloud Attack Surface Management plan at 65000.00 USD per year on a 12-month contract.

Verdict

PhishEye is a good fit for security, fraud and brand teams that need impersonation monitoring tied to a takedown process, especially MSPs that can use its child workspaces. Its strongest case is the combination of varied detection signals, channel coverage and tiered response capacity. Look elsewhere if a free ongoing service, guaranteed takedown outcomes or current formal certification is essential.

PhishEye plans and pricing

All plans
Free Free 1 monitored brand · 1 typosquat scan (single run) · 30-day scan history · no takedown cases / requests phisheye.com · 29 Sept 2026
Starter Not published 1 monitored brand · daily typosquat scans · 10 takedown cases · 60-day scan history phisheye.com · 29 Sept 2026
Pro Not published 3 monitored brands · 50 takedown cases · 90-day scan history · up to 5 child workspaces · up to 5 team members phisheye.com · 29 Sept 2026
Business Not published 10 monitored brands · unlimited takedown cases · 1-year scan history · up to 25 child workspaces · dedicated support & SLA phisheye.com · 29 Sept 2026

Compared on digital risk protection software

Free plan
Yesphisheye.com

Facts

Purpose
PhishEye detects phishing, typosquat and lookalike domains, brand abuse, and impersonation, and supports coordinated takedowns.phisheye.com · 29 Sept 2026
Detection signals
It combines domain, DNS, certificate, hosting, redirect, and live-page signals to identify active brand impersonation.phisheye.com · 29 Sept 2026
Channels
The service describes monitoring across domains, social, ads, search, and app stores.phisheye.com · 29 Sept 2026
Free tier limit
The Free plan includes one single-run typosquat scan on one brand and does not include takedown requests.phisheye.com · 29 Sept 2026
Takedowns
Paid plans list automated takedowns through GoDaddy and Cloudflare abuse APIs; PhishEye says it cannot guarantee third parties will accept reports or act within a timeframe.phisheye.com · 29 Sept 2026
Integrations
The Pro plan lists nine SIEM/SOAR connectors: Slack, Teams, Splunk, Sumo, Sentinel, Defender, ThreatConnect, Tines, and XSOAR.phisheye.com · 29 Sept 2026
Threat feed
Plans list STIX 2.1 / TAXII 2.1 threat-feed export.phisheye.com · 29 Sept 2026
Audience
PhishEye says it builds software for security, fraud, and brand teams, and its plans include child workspaces for MSP mode.phisheye.com · 29 Sept 2026
Security controls
The company says web and API connections use TLS 1.2 or higher, supported primary data stores are encrypted at rest, and administrative and production-facing accounts require MFA.phisheye.com · 29 Sept 2026
Certifications
The trust page says formal certifications such as SOC 2 Type II or ISO 27001 may be pursued as customer demand and company scale require.phisheye.com · 29 Sept 2026
Support
The trust page says it aims to keep the service available during UK business hours; Pro includes priority email support and Business includes dedicated support and an SLA.phisheye.com · 29 Sept 2026
Company
PhishEye Ltd is incorporated in England and Wales and lists its registered office at 17 Hanover Square, London W1S 1BN, United Kingdom.phisheye.com · 29 Sept 2026
Founder
The About page says PhishEye is built and run by its founder, Mohamed Hamed, and does not state a founding year.phisheye.com · 29 Sept 2026

Company

Headquarters
London, United Kingdomphisheye.com · 28 Sept 2026

Best PhishEye alternatives

See all 20

Where it ranks on Everything Xiaomi

Is PhishEye yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources