Dual-profile screenshots
The clean page served to a crawler and the credential trap served to a real mobile visitor — captured from the same URL.
A screenshot is easy to ignore. A cloaking diff, raw headers and a timestamped timeline are not. Phish Plug packages the proof that gets clones removed — accepted on first submission 99% of the time.
Inside a case
The clean page served to a crawler and the credential trap served to a real mobile visitor — captured from the same URL.
The two responses compared side by side, proving the hidden redirect that keeps the phishing page alive.
Unedited HTTP headers from both profiles, so desks can verify behaviour instead of trusting a picture.
The full hop-by-hop path to the trap, plus hosting, registrar and CDN details for routing.
Timestamped from first sighting to confirmed offline, giving an unbroken chain of custody.
Download the whole case or pull it over the API as structured JSON — ready for legal or the registrar.
Why it gets actioned
Abuse teams are flooded with low-quality reports. The ones they action first are the ones that prove the abuse without extra work. Phish Plug writes every case for that reader: the cloaking is shown, the headers are raw, the infrastructure is named, and the timeline is timestamped.
FAQ
Screenshots from both crawl profiles (search crawler and real mobile device), raw HTTP response headers, the cloaking diff that shows the two responses side by side, the resolved redirect chain, WHOIS and hosting details, and a timestamped Detected → Removed timeline. Everything needed for an abuse desk to act without asking questions.
A single screenshot is easy to dismiss — it proves nothing about how the page behaves or who is behind it. Desks need to see the cloaking, the headers and the infrastructure. Phish Plug packages exactly that, which is why 99% of our cases are accepted on first submission.
Timestamps, raw unedited headers, reproducible crawl parameters and an unbroken chain from detection to removal. Each artifact records when and how it was captured, so the case holds up to scrutiny rather than relying on a screenshot's word.
Yes. Every case exports as a bundle (and over the API as structured JSON) with all artifacts attached, so you can forward it to a registrar, hand it to legal, or archive it for your own records.
Cases are archived with their full evidence trail after removal, so you keep a durable record of every impersonation attempt against your brand and how it was resolved.
Yes — that is the core of it. The dual-profile capture shows the clean crawler page and the credential trap served to a real mobile visitor from the same URL, side by side, which is the proof most takedown desks act on fastest.
Run a free clone check on one domain and get back an evidence sample from an actual case.