Part of #285, #249, and meta #245.
Provider
PhishTank.
Fit
Phishing-specific provider. Useful only for phishing checks, not malware, domain age, TLS, or general reputation. Lower priority than URLhaus unless phishing-specific checks become a product goal.
Data Sent
The URL check API accepts the URL to check. Browser Picker should assume the full URL may be sent and disclose that before the request.
API / Terms Notes
PhishTank supports a URL check API with optional/recommended app keys. Rate limits are enforced and exposed through response headers such as X-Request-Limit-Interval, X-Request-Limit, and X-Request-Count. A descriptive User-Agent is expected.
Acceptance Notes
- Disabled by default.
- User-triggered only unless a future automatic-check setting explicitly enables phishing checks.
- Bring-your-own app key if implemented.
- Explain that this provider checks phishing reports, not general URL safety.
- Respect rate-limit headers and handle HTTP 509/rate-limit failures neutrally.
- Do not log submitted URLs or app keys.
- Do not automatically call this provider when a URL matches Defaults.
Out of Scope
- Treating a no-match as safe.
- Malware-focused reputation checks.
- RDAP or public CT history lookups.
Part of #285, #249, and meta #245.
Provider
PhishTank.
Fit
Phishing-specific provider. Useful only for phishing checks, not malware, domain age, TLS, or general reputation. Lower priority than URLhaus unless phishing-specific checks become a product goal.
Data Sent
The URL check API accepts the URL to check. Browser Picker should assume the full URL may be sent and disclose that before the request.
API / Terms Notes
PhishTank supports a URL check API with optional/recommended app keys. Rate limits are enforced and exposed through response headers such as X-Request-Limit-Interval, X-Request-Limit, and X-Request-Count. A descriptive User-Agent is expected.
Acceptance Notes
Out of Scope