Evidence

Evidence that
desks accept.

A screenshot is easy to ignore. A cloaking diff, raw headers and a timestamped timeline are not. Phish Plug packages the proof that gets clones removed — accepted on first submission 99% of the time.

case #4821 · aurora-bonus.net

artSHOT·Acrawler view — clean article page
artSHOT·Bmobile view — credential trap
artDIFFcloaking proven · redirect 181.20.x
artHEADERSraw HTTP · both profiles
artTIMELINEdetected 09:14 → removed 14:02
export bundle accepted first try

Inside a case

What every bundle contains

Dual-profile screenshots

The clean page served to a crawler and the credential trap served to a real mobile visitor — captured from the same URL.

Cloaking diff

The two responses compared side by side, proving the hidden redirect that keeps the phishing page alive.

Raw response headers

Unedited HTTP headers from both profiles, so desks can verify behaviour instead of trusting a picture.

Resolved redirect chain

The full hop-by-hop path to the trap, plus hosting, registrar and CDN details for routing.

Detected → Removed timeline

Timestamped from first sighting to confirmed offline, giving an unbroken chain of custody.

Exportable bundle

Download the whole case or pull it over the API as structured JSON — ready for legal or the registrar.

Why it gets actioned

Built for the desk on the other end

Abuse teams are flooded with low-quality reports. The ones they action first are the ones that prove the abuse without extra work. Phish Plug writes every case for that reader: the cloaking is shown, the headers are raw, the infrastructure is named, and the timeline is timestamped.

Raw, unedited headers Timestamped capture Reproducible crawl Infrastructure named
99%
Accepted first submission
37min
Median time to filing
6
Abuse channels covered
1,284
Clones taken down

FAQ

Evidence questions

What is in a Phish Plug evidence case?

Screenshots from both crawl profiles (search crawler and real mobile device), raw HTTP response headers, the cloaking diff that shows the two responses side by side, the resolved redirect chain, WHOIS and hosting details, and a timestamped Detected → Removed timeline. Everything needed for an abuse desk to act without asking questions.

Why do abuse desks reject weak reports?

A single screenshot is easy to dismiss — it proves nothing about how the page behaves or who is behind it. Desks need to see the cloaking, the headers and the infrastructure. Phish Plug packages exactly that, which is why 99% of our cases are accepted on first submission.

What makes evidence 'court-ready'?

Timestamps, raw unedited headers, reproducible crawl parameters and an unbroken chain from detection to removal. Each artifact records when and how it was captured, so the case holds up to scrutiny rather than relying on a screenshot's word.

Can I export a case?

Yes. Every case exports as a bundle (and over the API as structured JSON) with all artifacts attached, so you can forward it to a registrar, hand it to legal, or archive it for your own records.

How long is evidence kept?

Cases are archived with their full evidence trail after removal, so you keep a durable record of every impersonation attempt against your brand and how it was resolved.

Does the evidence prove mobile cloaking specifically?

Yes — that is the core of it. The dual-profile capture shows the clean crawler page and the credential trap served to a real mobile visitor from the same URL, side by side, which is the proof most takedown desks act on fastest.

See a real evidence sample

Run a free clone check on one domain and get back an evidence sample from an actual case.