
Echtzeit-Blocklist für Phishing- und Betrugsdomains - 208k+ kuratierte Bedrohungen, 1M+ Community, kostenlose API, mehrere Formate

Mit einem Klick zu Pi-hole oder AdGuard Home hinzufügen — fügen Sie diese URL in Ihre Blocklisten-Einstellungen ein:``` https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/hosts.txt
> **Der CDN-Link oben wird empfohlen** — bereitgestellt über das globale jsDelivr-CDN, ohne Ratenlimits.
> Raw-GitHub-Spiegel (kann bei starkem Traffic 429 zurückgeben): `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt`
> Weitere Formate: [Hosts](#-data-feeds) · [AdBlock](#-data-feeds) · [Dnsmasq](#-data-feeds) · [Unbound](#-data-feeds) · [RPZ](#-data-feeds) · [API](#-threat-intelligence-api)
<img src="https://assets.kitploit.com/production/public/readmes/9225/66755568f640f93051ca779dd85131a85bc03d6385f7c57bdaaf388de6854fbc.gif" width="100%">
## <img src="https://assets.kitploit.com/production/public/readmes/9225/375391e605e2336c5dda1b81c5194a94a192db9a096cf46c24c52a389dbd4d16.png" alt="Hochspannung" width="22" height="22" /> Schnellzugriff
<details>
<summary><b>Inhaltsverzeichnis</b></summary>
- [Schnellstart](#-quick-start)
- [Live-Statistiken](#live-statistics)
- [Daten-Feeds](#-data-feeds)
- [Root-Listen](#-root-lists)
- [Inhaltsverifizierte Feeds](#-content-verified-feeds-)
- [Threat-Intelligence-API](#-threat-intelligence-api)
- [Über Destroylist](#-about-destroylist)
- [Workflow & Behebung](#-threat-intelligence--automated-remediation-workflow)
- [Info für Betrugsopfer](#-key-info-for-online-fraud-victims)
- [Einspruchsverfahren](#-appeals-process)
- [Kontakt](#-connect-with-us)
- [Machen Sie mit](#-join-the-fight)
</details>
### Live-Statistiken
| Primary | Primary Live | Community | Community Live |
|:-------:|:------------:|:---------:|:--------------:|
|  |  |  |  |
| Primary Content | Community Content |
|:---------------:|:-----------------:|
|  |  |
| | Heute | Woche | Monat |
|:--|:-----:|:----:|:-----:|
| **Primary** |  |  |  |
| **Community** |  |  |  |
### <img src="https://assets.kitploit.com/production/public/readmes/9225/bb78fad734ffe1195b52ffbea506a7954009d8b8d2124a6f8c076aeedb2c5d84.png" alt="Dateiordner" width="22" height="22" /> Daten-Feeds
| Feed | Beschreibung | Update | Download |
|:-----|:------------|:------:|:--------:|
| **Primary** | Kuratierte Phishing-Domains | ⚡ Echtzeit | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.txt) |
| **Primary Live** | DNS-verifiziert aktiv | 🕐 24h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/active_domains.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/active_domains.txt) |
| **Community** | Aus 13+ Quellen aggregiert | 🕐 2h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/blocklist.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/blocklist.txt) |
| **Community Live** | Per Community-DNS verifiziert | 🕐 24h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/live_blocklist.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/live_blocklist.txt) |
| **Primary Content** | Kuratiert + HTTP-Inhalt verifiziert | 🕐 12h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/content_active.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/content_active.txt) |
| **Community Content** | Aggregiert + HTTP-Inhalt verifiziert | 🕐 24h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/content_live.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/content_live.txt) |
| **Allowlist** | Schutz vor Falschpositiven | ✋ Manuell | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/allow/allowlist.json) |
> [!TIP]
> **Produktion:** `list.json` oder `active_domains.json` · **Maximale Abdeckung:** `blocklist.json` · **Firewall/DNS:** Root-Listen
<details>
<summary>📁 <b>Alle Download-Formate</b> (TXT, Hosts, AdBlock, Dnsmasq, Unbound, RPZ)</summary>
<br>
> **Erhalten Sie 429-Fehler?** Verwenden Sie die jsDelivr-CDN-Links unten — sie umgehen die GitHub-Ratenlimits.
**Über jsDelivr CDN (empfohlen, keine Ratenlimits):**
| Format | Primary | Primary Live | Community | Community Live |
|:------:|:-------:|:------------:|:---------:|:--------------:|
| **TXT** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/domains.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/domains.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/domains.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/domains.txt) |
| **Hosts** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/hosts.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/hosts.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/hosts.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/hosts.txt) |
| **AdBlock** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/adblock.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/adblock.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/adblock.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/adblock.txt) |
| **Dnsmasq** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/dnsmasq.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/dnsmasq.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/dnsmasq.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/dnsmasq.conf) |
| **Unbound** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/unbound.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/unbound.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/unbound.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/unbound.conf) |
| **RPZ** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/rpz.zone) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/rpz.zone) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/rpz.zone) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/rpz.zone) |
| **Redis** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/redis.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/redis.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/redis.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/redis.txt) |
> **Redis-Einzeiler** — lädt die vollständige Liste in ein Redis-Set (atomarer Austausch, Neuladen ohne Ausfallzeiten):
> ```
> curl -s https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/redis.txt | redis-cli --pipe
> ```
> Prüfen Sie dann jede Domain in O(1): `SISMEMBER destroylist:primary evil-domain.com`
<details>
<summary>Über raw.githubusercontent.com (kann bei starkem Traffic 429 zurückgeben)</summary>
| Format | Primary | Primary Live | Community | Community Live |
|:------:|:-------:|:------------:|:---------:|:--------------:|
| **TXT** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/domains.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/domains.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/domains.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/domains.txt) |
| **Hosts** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/hosts.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/hosts.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/hosts.txt) |
| **AdBlock** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/adblock.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/adblock.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/adblock.txt) |
| **Dnsmasq** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/dnsmasq.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/dnsmasq.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/dnsmasq.conf) |
| **Unbound** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/unbound.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/unbound.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/unbound.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/unbound.conf) |
| **RPZ** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/rpz.zone) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/rpz.zone) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/rpz.zone) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/rpz.zone) |
</details>
> **Hosts** → Pi-hole, /etc/hosts, Windows · **AdBlock** → uBlock Origin, AdGuard · **Dnsmasq** → dnsmasq DNS · **Unbound** → pfSense, OPNsense · **RPZ** → BIND, Knot DNS · **Redis** → Massenimport per `redis-cli --pipe`
</details>
### <img src="https://assets.kitploit.com/production/public/readmes/9225/ce7d7fb4a40580532e4e27b60c441010f36f8f671cdfbb5e988e1258bd2c2bc5.png" alt="Laptop" width="22" height="22" /> Root-Listen
> [!TIP]
> **Nur Root-Domains** — keine Subdomains, Hosting-Anbieter ausgeschlossen
| | Alle Roots | Nur Live | Nur Dienste |
|:--|:-:|:-:|:-:|
| 🔴 **Primary** | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/active_root_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/active_root_domains.txt) | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/online_root_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/online_root_domains.txt) | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/services_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/services_domains.txt) |
| ⚫ **Community** | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_root_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_root_domains.txt) | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_online_root_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_online_root_domains.txt) | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_services_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_services_domains.txt) |
> **Alle Roots** — saubere Root-Domains (ohne Infrastruktur) · **Nur Live** — DNS-verifiziert aktiv · **Nur Dienste** — Subdomains von Hosting-Plattformen (Vercel, Pages.dev, Netlify usw.)
<img src="https://assets.kitploit.com/production/public/readmes/9225/66755568f640f93051ca779dd85131a85bc03d6385f7c57bdaaf388de6854fbc.gif" width="100%">
## <img src="https://assets.kitploit.com/production/public/readmes/9225/b6a803f28233508a8d026ca7dbf00c61ac4e5d863de24a7b164bc348c079cef8.webp" width="25" /> Inhaltsverifizierte Feeds <img src="https://assets.kitploit.com/production/public/readmes/9225/f9508aaeba939041deccda3064343b9e328d5722aac996f0efb873b9fc4885e4.webp" width="25" />
> [!NOTE]
> **Echte HTTP-Inhaltsverifizierung** — nicht nur DNS, sondern tatsächliche Erkennung von Phishing-Seiten
[](https://github.com/phishdestroy/destroylist/raw/main/dns/content_active.json)
[](https://github.com/phishdestroy/destroylist/raw/main/community/content_live.json)
| Feed | Update | Beschreibung |
|:-----|:------:|:------------|
| **Primary Content** | `12h` (06:00 / 18:00 UTC) | Kuratierte Phishing-Domains mit verifiziertem aktivem Inhalt |
| **Community Content** | `24h` (03:00 UTC) | Aggregierte Feeds mit verifiziertem aktivem Inhalt |
> Download-Links: siehe [Daten-Feeds](#-data-feeds) oben
> [!WARNING]
> **Cloaking-Warnung:** Betrüger nutzen Cloaking, um Phishing vor Bots zu verbergen — sie zeigen Scannern leere/gefälschte Seiten. Domain **NICHT** in der Inhaltsliste ≠ sicher! Nutzen Sie für umfassenden Schutz die vollständigen **Primary**- oder **Community**-Listen.
<img src="https://assets.kitploit.com/production/public/readmes/9225/66755568f640f93051ca779dd85131a85bc03d6385f7c57bdaaf388de6854fbc.gif" width="100%">
## <img src="https://assets.kitploit.com/production/public/readmes/9225/8473e35500f4880a4b221b0e6b9e0232c4cd8b95dd3e0e87c47b8d1d8456935f.webp" alt="Alien-Monster" width="25" height="25" /> Threat-Intelligence-API
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/9225/708e69fca236d3f5355650687e220e2d365289b763ddf4dadea90d99e53ec691.png" alt="API" width="700"/>
</p>```mermaid
%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%%
flowchart LR
Request["🌐 Client Request<br/>(Single / Bulk)"] e1@--> API["⚡ Live API<br/>api.destroy.tools"]
API e2@--> Engine["🧠 Threat Engine<br/>(Risk Score 0-100)"]
Engine e3@--> DB[("🗄️ Destroylist DB<br/>1M+ Threats")]
DB e4@--> Engine
Engine e5@--> Response["📋 JSON Response<br/>(Severity & Status)"]
classDef client fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF;
classDef api fill:#000000,stroke:#FF0000,stroke-width:2px,color:#FFFFFF;
classDef db fill:#000000,stroke:#333333,stroke-width:2px,stroke-dasharray: 5 5,color:#FFFFFF;
classDef animate stroke:#FF0000,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;
classDef animateDark stroke:#333333,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;
class Request client;
class API,Engine,Response api;
class DB db;
class e1,e2,e3,e5 animate;
class e4 animateDark;
Kostenlos, offen, ohne API-Schlüssel. Echtzeit-Domain-Risiko-Scoring (0-100) für 888K+ Bedrohungen · 2h-Sync · Einzel- & Massenprüfung (500/Anfrage) · Stichwortsuche · Vollständige Feeds
| Methode | Endpunkt | Beschreibung |
|---|---|---|
GET | /v1/check?domain= | Einzelne Domain-Prüfung mit Risiko-Score & Schweregrad |
POST | /v1/check/bulk | Massenprüfung von bis zu 500 Domains pro Anfrage |
GET | /v1/search?q= | Durchsuche Domains auf der Blockliste nach Stichwort |
GET | /v1/feed/{list} | Vollständige Domain-Feeds herunterladen (primär, Community, aktiv) |
GET | /v1/stats | Live-Statistiken & Domain-Anzahl |
Jede Domain erhält einen Risiko-Score (0-100) auf Basis mehrerer Signale:
🔴 Kritisch 70-100 · 🟠 Hoch 40-69 · 🟡 Mittel 20-39 · 🟢 Niedrig 1-19
cURL```bash curl "https://api.destroy.tools/v1/check?domain=suspicious-site.xyz"
**Python**```python
import requests
r = requests.get(f"https://api.destroy.tools/v1/check?domain={domain}")
if r.json()["threat"]:
print(f"BLOCKED: {r.json()['severity']} (score: {r.json()['risk_score']})")
JavaScript```javascript
const r = await fetch(https://api.destroy.tools/v1/check?domain=${domain});
const data = await r.json();
if (data.threat) console.warn("PHISHING:", data.severity, data.risk_score);
**Massenprüfung**```bash
curl -X POST "https://api.destroy.tools/v1/check/bulk" \
-H "Content-Type: application/json" \
-d '{"domains":["site1.com","site2.xyz","site3.top"]}'

[!NOTE] Die Live-Datenerfassung begann am 1. Juli 2025
888K+ verfolgte Domains · 13+ Bedrohungsquellen · 50+ Anbieterberichte · 6 Ausgabeformate · Kostenlose API
Destroylist ist eine Echtzeit-Bedrohungsintelligenz-Plattform von PhishDestroy – die Firewalls, DNS-Resolver, Browsererweiterungen und Sicherheitsteams weltweit schützt. Jede Domain wird entdeckt, verifiziert, den Registraren gemeldet und transparent veröffentlicht.
%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%% flowchart TB subgraph Sources["🔍 Threat Sources"] S1[30+ Parsers] S2[Community Feeds] S3[Telegram Bot] S4[CT Logs / DNS] end
subgraph Ingestion["📥 Ingestion"] I1[smart_aggregator.py] I2[validate_and_clean.py] end
subgraph Enrichment["🧠 Enrichment"] E1[DNS Validation] E2[HTTP Content Check] E3[VirusTotal / GSB] end
subgraph Distribution["📡 Distribution"] D1[JSON / TXT] D2[Hosts / AdBlock] D3[RPZ / Unbound] D4[API Feed] end
Sources --> Ingestion Ingestion --> Enrichment Enrichment --> Distribution
classDef source fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF; classDef ingest fill:#000000,stroke:#FF0000,stroke-width:2px,color:#FFFFFF; classDef enrich fill:#000000,stroke:#CC0000,stroke-width:2px,color:#FFFFFF; classDef dist fill:#000000,stroke:#FF0000,stroke-width:2px,stroke-dasharray: 5 5,color:#FFFFFF;
class S1,S2,S3,S4 source; class I1,I2 ingest; class E1,E2,E3 enrich; class D1,D2,D3,D4 dist;
<details>
<summary>🔧 <b>Schnelle Integrationsbeispiele</b> (Abonnement-URLs · curl · Python · Bash)</summary>
<br>
### Ein-Klick-Abonnement-URLs
| Tool | Format | URL |
|:-----|:------:|:----|
| **Pi-hole** | Hosts | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt` |
| **AdGuard Home** | AdBlock | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt` |
| **uBlock Origin** | AdBlock | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt` |
| **pfSense / OPNsense (Unbound)** | Unbound | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/unbound.conf` |
| **BIND / Knot DNS (RPZ)** | RPZ | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/rpz.zone` |
| **Dnsmasq** | Dnsmasq | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf` |
> **Pi-hole** — Einstellungen > Blocklisten > Hosts-URL einfügen<br>
> **AdGuard Home** — Filter > DNS-Blocklisten > Blockliste hinzufügen > AdBlock-URL einfügen<br>
> **uBlock Origin** — Einstellungen > Filterlisten > Importieren > AdBlock-URL einfügen<br>
> **pfSense** — Dienste > DNS-Resolver > Unbound-URL einfügen<br>
> **BIND/Knot** — RPZ-URL als Response-Policy-Zone hinzufügen
### curl-Einzeiler```bash
# Plain domain list
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/domains.txt -o domains.txt
# Hosts format (Pi-hole, /etc/hosts)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt -o hosts_blocklist.txt
# AdBlock format (uBlock Origin, AdGuard)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt -o adblock.txt
# Dnsmasq
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf -o dnsmasq_blocklist.conf
# Unbound (pfSense / OPNsense)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/unbound.conf -o unbound_blocklist.conf
# RPZ (BIND / Knot)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/rpz.zone -o rpz_blocklist.zone
import requests blocklist = requests.get('https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.json').json() is_malicious = "suspicious-domain.com" in blocklist
### Bash```bash
curl -s https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.txt | grep -q "suspicious-domain.com" && echo "BLOCKED"

%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%%
flowchart LR
Discover["🔍 DISCOVER
30+ Parsers"] e1@--> Report["📤 REPORT
50+ Vendors"]
Report e2@--> Legal["⚖️ LEGAL
ICANN Compliance"]
Legal e3@--> Publish["📡 PUBLISH
Real-time Feed"]
classDef box fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF; classDef animate stroke:#FF0000,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;
class Discover,Report,Legal,Publish box;
class e1,e2,e3 animate;
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/9225/b44d5f0758cb8b29e42734f5d032478fbc6c2c1574e5c5dbc1042c5551cb60da.png" alt="Workflow" width="700"/>
</p>
<div align="center">
| 🔍 **ENTDECKEN** | 📤 **MELDEN** | ⚖️ **RECHTLICH** | 📡 **VERÖFFENTLICHEN** |
|:---:|:---:|:---:|:---:|
| 30+ Parser | 50+ Anbieter | ICANN-Konformität | Echtzeit |
| CT-Logs, DNS | Google, Microsoft | Missbrauchsmeldungen | GitHub, Telegram |
| Soziale Medien | VirusTotal, Cloudflare | Beweispakete | Twitter, Mastodon |
</div>
<details>
<summary>📖 <b>Vollständige Workflow-Details lesen</b></summary>
<br>
### 🔍 Phase 1: Präventive Erkennung & Aufnahme
🔎 Wir nutzen ein verteiltes Netzwerk aus **30+ proprietären Parsern**, um bösartige Domains bereits im frühesten Stadium zu identifizieren:
- **Erweiterte Heuristiken:** Kontinuierliche Überwachung von Google Ads (Malvertising), SEO-manipulierten Suchergebnissen und angesagten Social-Media-Kampagnen auf Twitter (X), YouTube und Telegram
- **Infrastrukturanalyse:** Einsatz von *dnstwist* und Typosquatting-Erkennung, um ähnlich aussehende Domains zu erkennen, die etablierte Marken imitieren
- **Community-Intelligenz:** Echtzeit-Aufnahme von von der Community gemeldeten Bedrohungen über unseren Telegram-Bot und Partner-Intelligence-Feeds
---
### 📤 Phase 2: Beitrag zum globalen Ökosystem
Sobald eine Bedrohung bestätigt ist, übermitteln wir Daten an über **50 branchenführende Anbieter**:```
Cloudflare Google Safe Browsing Microsoft Security VirusTotal
Netcraft ESET Bitdefender Norton Safe Web
Avira PhishTank Dr.Web Yandex Safe Browsing
URLScan.io PolySwarm SiteReview Urlquery
PhishStats PhishReport IsItPhish ThreatCenter

💼 DestroyList zielt darauf ab, bösartige Domains zu deaktivieren: Betrugsseiten, Phishing und andere illegale Websites, um die Internetsicherheit zu erhöhen.
Bevor eine Domain hinzugefügt wird, führen wir Folgendes durch:
🔍 Wir scannen sie mithilfe von Cybersicherheitsplattformen auf Threat Intelligence.
📥 Wir senden eine offizielle Beschwerde an den Registrar und den Hosting-Anbieter (über WHOIS), einschließlich Scan-Ergebnissen, Screenshots und einer Aufforderung zur Untersuchung im Auftrag des Kunden. Die Beschwerde informiert sie außerdem über die Aufnahme in unsere öffentliche Datenbank.
🚔 Gemäß den ICANN-Regeln müssen Registrare solche Beschwerden innerhalb von 24 Stunden prüfen.
🦖 Wir arbeiten hart daran, Bedrohungen schnell zu beseitigen. Jede bösartige Domain wird transparent analysiert, dokumentiert, gemeldet und veröffentlicht.
Wenn eine Domain jedoch 10–30+ Missbrauchsmeldungen erhält und ein Registrar diese monatelang weiterhin ignoriert, ändert sich die Situation: Der Registrar ist keine passive Partei mehr. Er stellt effektiv Infrastruktur für illegale Aktivitäten bereit.
Manche Registrare verhalten sich so, als würden ihre internen Richtlinien die ICANN-Anforderungen und nationale Gesetze irgendwie außer Kraft setzen – als wären Phishing und Betrug „erlaubt“, solange sie persönlich entscheiden, nicht zu handeln.
👮 Wir dokumentieren dies öffentlich, damit jeder sehen kann: Bedrohungen bestehen fort, nicht weil sie unbemerkt blieben, sondern weil die verantwortlichen Anbieter schlicht beschlossen haben, nichts zu unternehmen.
Anfragen von Privatpersonen:
DestroyList ist ein Open-Source-, nichtkommerzielles Freiwilligenprojekt.
Privatpersonen können die Anzahl der Missbrauchsmeldungen anfragen, die wir für eine bestimmte Domain gesendet haben, jedoch nur über öffentliche Kanäle:
❗ Wir antworten nicht auf private E-Mail-Anfragen von Einzelpersonen bezüglich der Anzahl der Meldungen.
✔️ Dies ist eine rechtliche Anforderung für Transparenz und gleichberechtigten Zugang zu Informationen.
Offizielle Anfragen von Regierungs- oder Strafverfolgungsbehörden können privat beantwortet werden.
💔 Wenn du durch eine hier bereits gelistete Domain betrogen wurdest, prüfe deren Aufnahmedatum über den Commit-Verlauf oder über unsere Telegram-/Mastodon-Kanäle.
💬 Wenn der Betrug stattfand, nachdem die Domain bereits gelistet war, kann die Verzögerung des Registrars oder Hosts darauf hindeuten, dass diese eine Mitschuld am Verlust tragen. Auch zukünftige potenzielle Opfer können diese Nachlässigkeit öffentlich dokumentiert sehen.
🔞 Von Registraren und Hosts, die Betrugsoperationen tolerieren, kann vernünftigerweise erwartet werden, dass sie Opfern oder deren Rechtsvertretern helfen.

Netzwerksicherheit · Bedrohungsforschung · KI/ML-Training · Trendanalyse · Automatisierung
Point-in-time-Verlauf – jeder Zustand der Liste ist rekonstruierbar:
| Granularität | Wo | Aufbewahrung |
|---|---|---|
| Jede Änderung | Commit-Verlauf | Für immer (41.000+ Commits) |
| Tägliche Diff-Listen (hinzugefügt/entfernt) | changes/ | Für immer, durchsuchbar in der GitHub-Codesuche |
| Wöchentliche & monatliche Vollschnappschüsse | archives/ → Release-Assets | Neuere im Repository, ältere in das permanente Release ausgelagert |
[!TIP] 📩 Historisches Archiv (500.000+ Domains, 5+ Jahre archiviert): [email protected]

Falsch gelistet? Behebe es schnell:
Genauigkeit zuerst! 🔭



| Repository | Beschreibung |
|---|---|
| namesilo-evidence | Beweisarchiv – Untersuchung des NameSilo-Registrar-Missbrauchs |
| nicenic-evidence | Beweisarchiv – Untersuchung des NiceNIC-Registrar-Missbrauchs |
| trustname-evidence | Beweisarchiv – Untersuchung des TrustName-Registrar-Missbrauchs |
| ScamIntelLogs | Rohe Betrugs-Intelligence-Logs und IOC-Daten |
| DestroyScammers | Operationen zur Entlarvung und Störung von Betrügern |

MIT – Frei, offen, ganz deins!

Wir freuen uns über Beiträge:
Eröffne ein Issue oder PR – lass uns Phishing gemeinsam zerschlagen! 💪
| Signal | Punkte | Beschreibung |
|---|
| Kuratierte Blocklist | +40 | In primärer Destroylist |
| Von der Community gemeldet | +20 | Von Community-Quellen gemeldet |
| DNS aktiv | +30 | Domain wird derzeit aufgelöst |
| Mehrere Quellen | +10 | Durch mehrere Feeds bestätigt |
| Verdächtige Stichwörter | +5 je | metamask, wallet, airdrop, usw. |
| Riskante TLD | +5 | .xyz, .top, .club, .icu, usw. |