Sees what scanners miss
Dual-profile crawling resolves the cloak that lets ordinary scanners wave a phishing page through.
How it works
Four stages, one panel, no manual stitching. Here is exactly how a clone goes from first sighting to confirmed offline — and why cloaking never gets in the way.
Phish Plug watches newly registered domains, certificate logs, lookalike and homoglyph patterns, backlinks and search results around the clock. Anything resembling your brand's name, marks or login flow is captured for verification — before your customers ever see it.
Cloaked phishing shows one page to crawlers and another to real visitors. Phish Plug fetches each suspect twice — as a search bot and as a real in-country mobile device through its proxy pool — and diffs the two responses to expose and prove the hidden redirect.
The moment impersonation is confirmed, a case is built: screenshots from both crawl profiles, raw response headers, the cloaking diff and the resolved redirect chain. It is stored per case and exportable, designed to be accepted on first submission.
Each clone's host, registrar and CDN are resolved, and the report is formatted for the correct abuse desk. With one human approval it is sent across the right channels — then the case is tracked until the page is confirmed offline.
Step 2, up close
This is what cloaking looks like — and what Phish Plug compares, side by side, to prove the redirect that keeps a phishing page alive.
aurora-bonus.net/loginRe-enter your details to restore access.
EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COMWhy it works
Dual-profile crawling resolves the cloak that lets ordinary scanners wave a phishing page through.
The cloaking diff and raw headers turn a dismissible screenshot into a case that gets actioned — 99% accepted.
Reports go to the exact desk for that host and registrar, which is why median time to filing is 37 minutes.
FAQ
It continuously watches newly registered domains, certificate transparency logs, lookalike and homoglyph patterns, backlinks and search results. Anything that resembles your brand's name, marks or login flow is pulled in for verification.
Cloaked phishing serves two pages from one URL. Phish Plug fetches each suspect twice — as a search crawler and as a real in-country mobile device — then diffs the responses. When the mobile version is a credential trap and the crawler version is clean, the hidden redirect is proven.
Automation finds and prepares; a person decides. Requiring a one-click approval before anything is sent keeps accuracy high and guarantees a legitimate site is never reported by mistake. It is the difference between fast and reckless.
Each clone's hosting, registrar and CDN are resolved automatically, and the report is formatted for — and sent to — the correct abuse desk for that infrastructure. The right evidence goes to the right place, which is why desks act quickly.
Every case carries a live Detected → Removed timeline. Phish Plug re-checks the target until it confirms the page is offline, then archives the case with its full evidence trail.
Median time from detection to a filed, evidence-backed takedown is 37 minutes. Removal time then depends on the host, but routing the right evidence to the right desk is what keeps it short.
Run a free clone check and see detection, cloaking forensics and evidence in one pass.