These routes require an Enterprise account with the Dark Web Monitoring module. They are limited to 60 requests per minute.

Endpoints

Date filters use DD/MM/YYYY. Potential phishing and typosquatting use q, not query.
Potential phishing
Compromised credentials

Response handling

  • Potential phishing pages can contain up to 1,000 records.
  • Typosquatting pages contain 10 records.
  • Preserve record IDs, source, first-seen, and last-seen values.
  • Treat domains as review candidates, not confirmed phishing.
  • Redact passwords and unrelated personal data before logging or ticketing.
  • Do not use exposed credentials to access another system.
See Monitor Brand Impersonation for domain candidates and Credential Response for privacy-reduced credential handling.