Pricing
Plans that end
the impersonation
Monitoring, cloaking forensics and human-approved takedowns — priced per protected brand, with no cap on how many clones we remove.
Free clone check
One domain, cloaking diff and an evidence sample included.
Single brand
One brand, watched around the clock.
- 24/7 monitoring for clones and lookalike domains
- All six takedown channels: registrar, host, CDN and Safe Browsing
- Cloaking forensics with dual-profile crawling
- Human-approved sending — nothing leaves without a click
- Evidence archive: screenshots, headers and diffs
Multi-brand
Most popularPortfolios and high-value brands.
- Everything in Single brand, for up to five brands
- Priority filing — 37 min median time to filing
- In-country proxy pool for cloaking forensics
- API access to cases, diffs and Detected → Removed status
- Portfolio dashboard across all brands
Enterprise
- Unlimited brands and domains
- Dedicated abuse-desk relationships
- On-prem in-country proxy pool
- SSO, audit log and response SLA
Why Phish Plug
Three ways to fight a phishing clone
| Capability | Manual takedowns | Generic domain monitoring | Phish Plug |
|---|---|---|---|
| Finds lookalike clones | |||
| Defeats mobile cloaking | |||
| Court-ready evidence bundle | Partial | ||
| Routes to the right abuse desk | Partial | ||
| No cap on takedowns | Partial | N/A | |
| Median time to filing | Hours–days | Alert only | 37 minutes |
| Human approval before sending | N/A |
FAQ
Pricing questions
What does the free clone check include?
One domain, scanned end to end: we look for active clones and lookalikes, run a cloaking diff on anything suspicious, and hand back an evidence sample so you can see exactly what a real takedown case looks like. No card required.
How is a brand counted?
A brand is one name and its associated domains and marks that you want watched. The Single plan covers one brand; Multi-brand covers up to five; Enterprise is unlimited. Lookalikes and clones of a covered brand do not count against your limit — we want you to find as many as exist.
What is the difference between monthly and yearly billing?
Yearly billing is the same platform at a lower effective rate — roughly 20% off the monthly price, billed once a year. You can switch billing period at any time; nothing about detection, evidence or takedowns changes.
Is there a limit on takedowns?
No. Every plan files as many evidence-backed takedowns as your clones require, across all six abuse channels. We price on the number of brands protected, not on how many clones we remove — because capping takedowns would defeat the point.
Do real sites ever get reported by mistake?
No. Detection is always followed by verification, and nothing is sent without a one-click human approval. The cloaking diff and evidence have to confirm impersonation first, which is how we keep a 99% evidence-accepted rate without touching legitimate sites.
Can I integrate Phish Plug with my own tools?
Yes. Multi-brand and Enterprise include API access to cases, cloaking diffs and Detected → Removed status, so you can pull everything into your SIEM, ticketing or brand-protection stack. Enterprise adds SSO, an audit log and a contractual response SLA.
What happens after I start?
Monitoring begins immediately. New domains, lookalikes and search results are watched around the clock; the first cases usually surface within hours. You approve sends from the panel, and every threat shows a live timeline from first sighting to confirmed removal.
Start with a free clone check
See one of your domains scanned, cloaking resolved and evidence captured — before you pay anything.