PhishEye
No phone app
in Digital Risk Protection Software
- Recognised40% of the score61
- Phone app26% of the score0
- Documented20% of the score93
- Free plan14% of the score100
- Free plan
- Yes
- Runs on
- api, Web
Summary
PhishEye detects phishing, typosquat and lookalike domains, brand abuse, and impersonation, and supports takedown workflows. It combines domain, DNS, certificate, hosting, redirect, and live-page signals to identify active brand impersonation. Monitoring covers domains, social channels, ads, search, and app stores. The Free plan includes one single-run typosquat scan for one brand and does not include takedown requests. Paid plans list automated takedowns through GoDaddy and Cloudflare abuse APIs, though PhishEye cannot guarantee that third parties will accept reports or act within a timeframe. Pro lists nine SIEM/SOAR connectors, and plans include STIX 2.1 / TAXII 2.1 threat-feed export. PhishEye offers web and API access and describes its audience as security, fraud, and brand teams. Its plans include child workspaces for MSP mode. The company says web and API connections use TLS 1.2 or higher, supported primary data stores are encrypted at rest, and administrative and production-facing accounts require MFA. Formal certifications may be pursued as customer demand and company scale require.
Who it is for
PhishEye suits security, fraud, and brand teams monitoring impersonation and related threats. Plans with child workspaces may also be relevant to MSP use.
What is good
- Monitoring spans domains, social, ads, search, and app stores.
- Detection combines six types of technical signals.
- Plans include STIX 2.1 / TAXII 2.1 export.
- Pro lists nine SIEM/SOAR connectors.
- API access is available.
What to know first
- Free offers only one single-run scan.
- Free does not include takedown requests.
- Third-party takedown actions are not guaranteed.
- Formal certifications may be pursued later.
Samsung Mobile US Press review
PhishEye: the full review
PhishEye combines brand threat monitoring with takedown workflows and threat-feed export. The free tier is a narrow single-run scan, and takedowns depend on third parties accepting and acting on reports.
Overview
PhishEye is a web and API service for finding phishing, lookalike domains and other forms of brand impersonation, with tools to coordinate takedowns. It is best suited to security, fraud and brand teams that need monitoring tied to a response workflow, including MSPs managing client workspaces. The one-time free scan is useful for an initial check, but ongoing monitoring and takedown cases require a paid plan.
Key features
PhishEye draws on domain, DNS, certificate, hosting, redirect and live-page signals to identify active brand impersonation. That breadth makes it more relevant to teams investigating suspicious sites than a tool focused only on domain-name matches. Monitoring spans domains, social, ads, search and app stores; the service also offers dark web monitoring, credential leak alerts and impersonation monitoring.
Paid plans include automated takedown workflows through GoDaddy and Cloudflare abuse APIs. This gives teams a path from finding a threat to submitting a response, but the providers may reject reports or take an unspecified time to act. Plans also list STIX 2.1 / TAXII 2.1 threat-feed export. Pro adds nine SIEM/SOAR connectors—Slack, Teams, Splunk, Sumo, Sentinel, Defender, ThreatConnect, Tines and XSOAR—so it is the more suitable tier for teams that need to route findings into existing security workflows.
Security controls include TLS 1.2 or higher for web and API connections, encryption at rest for supported primary data stores, and MFA for administrative and production-facing accounts. PhishEye says it may pursue formal certifications such as SOC 2 Type II or ISO 27001 as demand and company scale require; organizations that require one of those certifications should weigh that carefully. Support aims to cover UK business hours. Pro includes priority email support, while Business adds dedicated support and an SLA.
Pricing
The Free plan costs 0.00 USD per free and provides one monitored brand, one single-run typosquat scan and 30-day scan history, with no takedown cases or requests. It is a useful initial check, not a monitoring plan: teams needing repeat scans, incident handling or takedowns must move to a paid tier.
Starter has custom pricing and covers one monitored brand, daily typosquat scans, 10 takedown cases and 60-day scan history. It suits a single-brand team that needs ongoing scanning and a modest case allowance, but it does not offer the multi-brand or workspace capacity of higher plans.
Pro also has custom pricing. It raises coverage to three monitored brands and 50 takedown cases, extends scan history to 90 days, and supports up to five child workspaces and five team members. Its connectors and priority email support make it a more capable option for teams integrating monitoring into security operations or managing several clients.
Business has custom pricing and includes 10 monitored brands, unlimited takedown cases, one-year scan history, up to 25 child workspaces, dedicated support and an SLA. It is the clearest fit for larger operations or MSPs with many client environments; the tradeoff is that even this tier caps monitored brands at 10.
Platforms
PhishEye is available on web and through an API. The API option supports teams incorporating the service into their own workflows, while the web interface offers a direct route for teams managing monitoring and cases.
Who it's for
PhishEye is aimed at security, fraud and brand teams that want brand-threat monitoring connected to takedown handling and threat-feed export. Child workspaces in Pro and Business make it relevant to MSPs separating client work. It is a weaker fit for a buyer seeking guaranteed removal, a substantial no-cost monitoring service, or a vendor already holding a required formal certification.
Pros and cons
- Pros: Multiple technical signals and monitoring across domains, social, ads, search and app stores address more than typosquatted domains alone.
- Pros: Paid takedown workflows, threat-feed export and, at Pro, nine SIEM/SOAR connectors can connect detection to existing response processes.
- Pros: Pro and Business include child workspaces, providing explicit capacity for MSP-style client management.
- Cons: Free is restricted to one single-run scan on one brand and provides no takedown requests, so it cannot serve as ongoing protection.
- Cons: Takedowns depend on third parties accepting reports and acting; submission does not guarantee removal or a response time.
- Cons: Paid plan prices are custom, and formal certifications such as SOC 2 Type II or ISO 27001 may be pursued rather than established commitments.
Alternatives
Consider SOCRadar Extended Threat Intelligence Platform if a published monthly price for dark web monitoring matters: its Essential plan is 600.00 USD per month (billed Monthly) for one domain and one seat, while its Business plan is 1145.00 USD per month. Choose Allure Brand Protection when flat-rate pricing without per-incident fees or takedown limits is the priority; coverage varies by plan and organization needs.
Constella Hunter+ is another paid alternative with pricing available by demo request. Flare may suit a buyer who wants to start with a free 14-day trial; it requires an identity verification call and is scoped to the customer's domain. For a tailored package, consider ZeroFox Attack Surface Intelligence, which uses quote-based pricing.
Fortra Data Security Posture Management is a paid option with no free plan or trial; its Advanced plan targets mid-sized or evolving security environments and includes enhanced support and required Quick Start Implementation. Group-IB Attack Surface Management offers a free trial, with Standard pricing based on the total number of confirmed external assets. KELA Platform offers a 30-day free trial with no commitment or payment details required, as well as a Cloud Attack Surface Management plan at 65000.00 USD per year on a 12-month contract.
Explore more options in Digital Risk Protection Software and Dark Web Monitoring Services.
Verdict
PhishEye is a sensible choice for security, fraud and brand teams—and MSPs—that need multi-signal brand monitoring connected to takedown workflows, especially when feed export or Pro's integrations matter. Its main limitation is the gap between submitting a takedown and securing action from a third party, compounded by custom pricing for paid plans. Choose it for the combined monitoring and response workflow; look elsewhere if guaranteed removals, established formal certifications or a clearly priced paid tier are essential.
PhishEye plans and pricing
All plansCompared on digital risk protection software
- Free plan
- Yesphisheye.com
Facts
- Purpose
- PhishEye detects phishing, typosquat and lookalike domains, brand abuse, and impersonation, and supports coordinated takedowns.phisheye.com · 29 Sept 2026
- Detection signals
- It combines domain, DNS, certificate, hosting, redirect, and live-page signals to identify active brand impersonation.phisheye.com · 29 Sept 2026
- Channels
- The service describes monitoring across domains, social, ads, search, and app stores.phisheye.com · 29 Sept 2026
- Free tier limit
- The Free plan includes one single-run typosquat scan on one brand and does not include takedown requests.phisheye.com · 29 Sept 2026
- Takedowns
- Paid plans list automated takedowns through GoDaddy and Cloudflare abuse APIs; PhishEye says it cannot guarantee third parties will accept reports or act within a timeframe.phisheye.com · 29 Sept 2026
- Integrations
- The Pro plan lists nine SIEM/SOAR connectors: Slack, Teams, Splunk, Sumo, Sentinel, Defender, ThreatConnect, Tines, and XSOAR.phisheye.com · 29 Sept 2026
- Threat feed
- Plans list STIX 2.1 / TAXII 2.1 threat-feed export.phisheye.com · 29 Sept 2026
- Audience
- PhishEye says it builds software for security, fraud, and brand teams, and its plans include child workspaces for MSP mode.phisheye.com · 29 Sept 2026
- Security controls
- The company says web and API connections use TLS 1.2 or higher, supported primary data stores are encrypted at rest, and administrative and production-facing accounts require MFA.phisheye.com · 29 Sept 2026
- Certifications
- The trust page says formal certifications such as SOC 2 Type II or ISO 27001 may be pursued as customer demand and company scale require.phisheye.com · 29 Sept 2026
- Support
- The trust page says it aims to keep the service available during UK business hours; Pro includes priority email support and Business includes dedicated support and an SLA.phisheye.com · 29 Sept 2026
- Company
- PhishEye Ltd is incorporated in England and Wales and lists its registered office at 17 Hanover Square, London W1S 1BN, United Kingdom.phisheye.com · 29 Sept 2026
- Founder
- The About page says PhishEye is built and run by its founder, Mohamed Hamed, and does not state a founding year.phisheye.com · 29 Sept 2026
Company
- Headquarters
- London, United Kingdomphisheye.com · 28 Sept 2026
Best PhishEye alternatives
See all 12Where it ranks on Samsung Mobile US Press
Is PhishEye yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- phisheye.com· checked 29 Sept 2026
- phisheye.com/pricing· checked 29 Sept 2026
- phisheye.com/about· checked 29 Sept 2026
- phisheye.com/trust· checked 29 Sept 2026




