BYTETOOLS

FishFish API

Free FishFish API with no key: a community-curated list of phishing and scam domains targeting gaming and chat platforms, updated continuously. Plain JSON array of domains.

No API key requiredHTTPSFree tier

Endpoint tested and returned HTTP 200 on 21 Aug 2026

What is the FishFish API?

The FishFish API is a free, key-free service publishing a community-curated blocklist of phishing and scam domains. The public read endpoint returns a plain JSON array of domain names, focused on scams impersonating gaming and chat platforms such as Discord, Steam and Roblox.

FishFish grew out of the Discord anti-scam community, where the same handful of attack patterns repeat endlessly: typosquatted brand names, fake Nitro giveaways, counterfeit Steam trade sites. Its list reflects that specialisation and the sample bears it out — `steamcrommunity.com`, `dlscord-to.xyz`, `robloox.cfd` and hundreds more homoglyph and typo variants. For anyone moderating a community platform this is far more targeted than a general phishing feed.

The read endpoint is deliberately trivial: no key, no pagination, just an array of strings you can load into a set. Write access — submitting or reviewing domains — requires a token and a trusted role, which is what keeps the list curated rather than crowdsourced chaos. As with any blocklist, expect the coverage to be narrow by design and the entries to churn as scam domains are registered and burned within days. Refresh regularly, match on the registrable domain rather than the full hostname, and treat it as one layer rather than a complete defence.

Quick facts

Base URL
https://api.fishfish.gg/v1
Authentication
No API key or account for read endpoints. Submitting domains requires a token and a trusted role. The list is a community project offered for anti-abuse use.
Rate limit
No published limit on the read endpoints. The list changes continuously but not by the second — refreshing every few minutes is ample.
Pricing
Free, with no registration for reading.
CORS
Not enabled — call it from your server
Official docs
Read the docs

How to use the FishFish API

Every request below was executed against the live API on 21 Aug 2026, and the response shown is the real body it returned — not an illustration.

1. Fetch the full phishing domain blocklist

GET https://api.fishfish.gg/v1/domains

curl
curl 'https://api.fishfish.gg/v1/domains' \
  -H 'Accept: application/json'
JavaScript (fetch)
const res = await fetch("https://api.fishfish.gg/v1/domains", {
  headers: {
    "Accept": "application/json",
  },
});
if (!res.ok) throw new Error(`Request failed: ${res.status}`);
const data = await res.json();
console.log(data);
Python (requests)
import requests

headers = {
    "Accept": "application/json",
}

res = requests.get("https://api.fishfish.gg/v1/domains", headers=headers, timeout=20)
res.raise_for_status()
print(res.json())
Response — HTTP 200 (truncated)
[
  "coinjeto.com",
  "betacsgo2.me",
  "tinytaskdapp.vercel.app",
  "stemcomnnmunnity.com",
  "disc-ogifts.gq",
  "robloox.cfd",
  "hoavax.com",
  "moderator-registration.com",
  "com-eng.eu",
  "steanmcomnmunity.com",
  "faze1.xyz",
  "counter-strike2023.com",
  "jobcordcompany.com",
  "join-formulary-moderator-test.com",
  "steamcrommunity.com",
  "academy-connects-moderetors.com",
  "app-discord-nitro.ru",
  "steamcommunicty.ru",
  "slreamcumnnunytl.com",
  "rbxbots.com",
  "zuki-bots.vercel.app",
  "dlscord-to.xyz",
  "nitrosteamf.com",
  "staemconmnuity.com",
  "track-addpkg.com",
  "vulcan-security.xyz",
  "cs2-sourse.com",
  "rustgiveaway.online",
  "web3whales.website",
  "blockdexsystems.pages.dev",
  "sttreamcommunity.ru",
  "official-form-hypesquad-events.com",
  "roblox.sh",
  "mysteryclick31g.vercel.app",
  "shortd.xyz",
  "s.teamdk.world",
  "go-1win.bet",
  "dirscod-drop.gq",
  "steemcommunyty.ru",
  "no15249880013.asia",
  "added-hypesquad.com",
  "gifltdilscorw.com",
  "mee6web3.com",
  "steaemcommunuity.com",
  "steamcommuhitiy.ru",
  "webkava.com",
  "tv-bonus.pro",
  "foloke.top",
  "steamcommuniqy.ru",
  "easydropper.ru",
  "join-the-formulary-hypesquad.cf",
  "freelisskins.ru",
  "dlscord-app.site",
  "steamcommunityid.ru",
  "pubggift.top",
  "steanncommuniti.store",
  "steacmcommunilty.com",
  "elon-giveaway.info",
  "role-management.com",
  "dicsord-q.ru",
  "enter-hypesquad-resgistration.gq",
  "opensea-click28-two.vercel.app",
  "steancommiuniliy.ru.com",
  "ravoxbet.com",
  "stearncomnunlty.shop",
  "steamcomuniltty.com",
  "steam-gifts.sbs",

Parameters

ParameterTypeRequiredDescription
(endpoint) /domainspathOptionalThe full blocklist as a JSON array of domain strings. /v1/domains
fullqueryOptionalReturn full domain objects with category, description and timestamps instead of bare strings. true
categoryqueryOptionalFilter by classification, such as `phishing` or `malware`. phishing
(endpoint) /domains/{domain}pathOptionalCheck a single domain and get its record if listed. /v1/domains/example.com
(endpoint) /urlspathOptionalThe companion list of specific malicious URLs rather than whole domains. /v1/urls

Response fields

(array of strings)array
The default response is a bare JSON array of domain names, ready to load into a set.
namestring
With `full=true`, the domain name.
categorystring
Classification such as `phishing` or `malware`.
descriptionstring
Reviewer's note on what the domain does.
added / checkedinteger
Unix timestamps for when the domain was listed and last verified.
targetstring
Which brand or platform the scam impersonates, where recorded.

What you can build with the FishFish API

  • Block scam links in a chat platform or community server
  • Warn users before they follow a known phishing link
  • Enrich moderation tooling with a targeted blocklist
  • Feed a DNS sinkhole aimed at gaming-related scams
  • Cross-check a reported domain against a curated list

Common errors and how to fix them

Very large response

The full list is thousands of domains in one array.

Fix: Fetch periodically and cache in a set. There is no pagination because the payload is only a few hundred kilobytes.

Domain not listed

Coverage is narrow and deliberately so.

Fix: The list targets gaming and chat platform scams. Combine it with broader phishing feeds for general web protection.

Stale matches

Scam domains are registered and abandoned within days.

Fix: Refresh regularly. An old cached copy will both miss new domains and block ones long since dead.

Subdomain mismatch

Entries are registrable domains, not full hostnames.

Fix: Normalise a URL to its registrable domain before matching, or you will miss `login.scam-domain.tld` style variants.

FishFish API — frequently asked questions

Is the FishFish API free?

Yes, reading the blocklist is free with no key or account. Submitting domains requires a token and a trusted reviewer role, which is what keeps the list curated.

What kinds of domains does it list?

Phishing and scam domains targeting gaming and chat communities — typosquats of Discord, Steam and Roblox, fake giveaway sites, counterfeit trading platforms and crypto scams aimed at the same audience.

Is this a general-purpose phishing blocklist?

No, and it does not claim to be. Its value is depth in a specific niche. For general web protection you want it alongside broader feeds rather than instead of them.

How often should I refresh the list?

Every few minutes is more than enough. Scam domains are registered and burned within days, so a stale copy misses new threats while carrying dead entries.

Tools that pair with this API

Alternatives to FishFish API

If FishFish does not fit, these security & auth apis cover similar ground. Every one was called before publishing, and each links to its own reference page with a working curl command and the response it returned.

APIWhat it doesAuthCORSLast verified
Pwned PasswordsFree Have I Been Pwned password API with no key. Check if a password appears in known breaches using k-anonymity — the password never leaves your server. Tested.No keyYes19 Aug 2026
Have I Been Pwned BreachesFree Have I Been Pwned breach list API with no key: every catalogued data breach with date, affected accounts and compromised data types. Tested curl example.No keyYes19 Aug 2026
NVD CVEFree NIST National Vulnerability Database API: search CVEs by id, keyword, severity, CVSS score and date with full descriptions and references. Tested example.No keyYes19 Aug 2026
CIRCL CVE SearchFree CIRCL CVE Search API with no key: query vulnerabilities by id, vendor or product, and pull the latest published CVEs. CORS enabled. Tested example.No keyYes19 Aug 2026
Google Public DNSFree Google DNS-over-HTTPS API with no key: resolve any DNS record type as JSON, with DNSSEC validation. Query DNS from the browser. Tested example.No keyYes20 Aug 2026
HashifyFree hashing API with no key: generate MD5, SHA-1, SHA-256 and other digests over HTTP in hex or base64. Tested curl example and security guidance.No keyNo19 Aug 2026
All Security & Auth APIs

FishFish is an independent third-party service and is not affiliated with ByteTools or ByteVancer. Details on this page were verified on 21 Aug 2026; always check the official documentation before relying on this API in production, as terms and limits can change.