Blog
What we found, how we measured it, and where we were wrong.
We publish the work rather than opinions about the category. Every piece here comes out of something we built or measured, and each one names a limit — including the detector bug that nearly had us accuse a real company.
Articles
Everything we have published
- Research2026-08-28 · 5 min read
We attributed live phishing pages to six brands. Every one was already gone.
What happened when we went back to preserve evidence for pages we had found hours earlier — and why it changed what we think this product is.
- Method2026-08-05 · 5 min read
The free certificate log everyone depends on is down more than it is up
crt.sh is the only free substring search over Certificate Transparency, it fails constantly, and most tools built on it report a clean result when it does. What we did instead.
- Method2026-07-16 · 4 min read
Our detector called a legitimate company a phishing site. Here is the bug.
A scoring flaw rated ordinary subdomains of an unrelated business as credential harvesting at 0.85. What caused it, and why this class of error is the one that matters.
- Guide2026-07-02 · 4 min read
What a registrar actually needs before they will suspend a domain
Most takedown notices fail because they assert resemblance. Abuse desks act on reproduction, and the difference is four specific checks.
- Guide2026-06-24 · 4 min read
Domain age is the strongest free signal, and almost nobody checks it
Credential-harvesting domains are days old. Here is how to read a registration record, what redaction actually means, and why certificate age is sharper still.
- Guide2026-06-11 · 3 min read
How to read a web address, and why almost everyone reads it wrong
The single rule that defeats most phishing links, explained properly — plus the four checks worth doing before you type anything into a page.
- Research2026-05-21 · 4 min read
Fake job postings are a brand problem, and nobody owns it
Recruitment fraud impersonating real employers harvests identity documents from candidates. The damage lands on the company being impersonated, which usually never finds out.
- Research2026-05-07 · 3 min read
Detection count is a vanity metric. Ask your vendor for these three instead.
Every brand-protection report leads with threats detected. It is the easiest number to inflate and the least connected to any outcome. Three questions that are harder to dodge.