PhishEye detects phishing, typosquat and lookalike domains, brand abuse, and impersonation, and supports takedown workflows. It combines domain, DNS, certificate, hosting, redirect, and live-page signals to identify active brand impersonation. Monitoring spans domains, social channels, ads, search, and app stores. The Free plan provides one single-run typosquat scan on one brand, with 30-day scan history and no takedown cases or requests. Paid plans list automated takedowns through GoDaddy and Cloudflare abuse APIs, but PhishEye cannot guarantee that third parties will accept reports or act within a timeframe. Pro lists nine SIEM/SOAR connectors, and plans include STIX 2.1 / TAXII 2.1 threat-feed export. The service offers web and API access. PhishEye says it builds software for security, fraud, and brand teams; plans also include child workspaces for MSP mode. The company describes TLS 1.2 or higher for web and API connections, encryption at rest for supported primary data stores, and MFA for administrative and production-facing accounts. Formal certifications such as SOC 2 Type II or ISO 27001 may be pursued as customer demand and company scale require.
Who it is for
PhishEye suits security, fraud, and brand teams monitoring for impersonation and coordinating takedowns. Its child workspaces also suit MSP-mode use.
What is good
- Monitoring covers domains, social, ads, search, and app stores.
- Detection combines domain, DNS, certificate, hosting, redirect, and live-page signals.
- Plans include STIX 2.1 / TAXII 2.1 threat-feed export.
- Administrative and production-facing accounts require MFA.
What to know first
- Free plan provides only one single-run scan on one brand.
- Free plan does not include takedown requests.
- Third parties may not accept reports or act within a timeframe.
- Formal certifications may be pursued, not stated as held.
The Geeks Club review
PhishEye: the full review
PhishEye combines multi-signal monitoring with takedown support and threat-feed options. Readers should note the free scan limit and that third parties control whether takedown reports lead to action.
Overview
PhishEye is a web and API service for identifying phishing, lookalike domains and other forms of brand impersonation. It is best suited to security, fraud and brand teams that want monitoring connected to takedown workflows, including MSPs overseeing client workspaces. The free option is limited to a single scan; teams needing continued monitoring or takedown cases will need a paid plan.
Key features
PhishEye assesses domain, DNS, certificate, hosting, redirect and live-page signals to identify active impersonation. That breadth is useful for teams investigating threats that may not be apparent from a suspicious domain name alone. Monitoring spans domains, social, advertising, search and app stores, alongside dark web monitoring, credential leak alerts and impersonation monitoring.
Paid plans include automated takedown requests through GoDaddy and Cloudflare abuse APIs. This provides a route from detection to response, but the relevant providers decide whether to accept reports and when to act. Plans also include STIX 2.1 / TAXII 2.1 threat-feed export. Pro adds nine SIEM/SOAR connectors—Slack, Teams, Splunk, Sumo, Sentinel, Defender, ThreatConnect, Tines and XSOAR—making it the clearest fit for teams that need to route alerts into established security workflows.
PhishEye says its web and API connections use TLS 1.2 or higher, supported primary data stores are encrypted at rest, and administrative and production-facing accounts require MFA. Its trust page says formal certifications such as SOC 2 Type II or ISO 27001 may be pursued as customer demand and company scale require. Organizations that require those certifications today should weigh that carefully. The service aims for availability during UK business hours; Pro includes priority email support, while Business includes dedicated support and an SLA.
Pricing
PhishEye’s Free plan costs 0.00 USD per free. It covers one monitored brand, one single-run typosquat scan and 30-day scan history, but excludes takedown cases and requests. That makes it a narrow first check rather than an ongoing protection plan. The service also advertises a 14-day trial.
Starter has custom pricing and provides one monitored brand, daily typosquat scans, 10 takedown cases and 60-day scan history. It suits a team that wants recurring checks and a limited response allowance without expanding brand coverage. Pro also has custom pricing; it raises coverage to three brands and 50 takedown cases, extends history to 90 days, and supports up to five child workspaces and five team members. Its connectors and priority email support make it more appropriate for security teams integrating monitoring into their operations.
Business has custom pricing and offers 10 monitored brands, unlimited takedown cases, one-year scan history, up to 25 child workspaces, dedicated support and an SLA. It is the strongest fit for larger programs or MSPs managing multiple clients, though its broader capacity may be unnecessary for a single-brand team. The lower paid tiers give up brand capacity, case volume, history, workspace or staffing limits, or higher-tier support depending on the plan.
Platforms
PhishEye is available on web and through an API. The API option suits teams that want to connect the service with their own tools or workflows; Pro’s named SIEM/SOAR connectors provide a more direct path for supported integrations.
Who it's for
The service is aimed at security, fraud and brand teams tracking impersonation and coordinating responses. Child workspaces in Pro and Business make it relevant to MSPs, with Business allowing more client workspaces. The single-brand Free plan is appropriate for an initial scan, but not for teams that need recurring monitoring or takedown handling.
Pros and cons
- Broad detection signals: Domain, infrastructure and live-page signals give investigators more than domain-name matching to work with.
- Monitoring and response in one service: Paid takedown workflows and threat-feed export connect detection to operational follow-up, while third-party action remains outside PhishEye’s control.
- Meaningful Pro integrations: Nine named SIEM/SOAR connectors can suit teams with established alert-routing workflows.
- Very limited free tier: One single-run scan for one brand cannot support ongoing monitoring, and it includes no takedown requests.
- Custom pricing on paid tiers: Starter, Pro and Business capacities are defined, but teams must seek pricing to compare their costs.
- Formal certifications may be pursued later: Organizations with a present requirement for SOC 2 Type II or ISO 27001 should consider another fit.
Alternatives
For a freemium option with a clearly priced entry point, SOCRadar Extended Threat Intelligence Platform has an Advanced Dark Web Monitoring Essential plan at 600.00 USD per month, billed monthly, for one domain and one seat. Choose it when that defined monthly price and scope are a better match than PhishEye’s custom-priced paid tiers.
Flare offers a 14-day trial at 0.00 USD per free, scoped to your domain, with no payment information required but an identity verification call required. It is an option for readers comparing trial access; PhishEye’s free tier instead provides a single-run scan.
Group-IB Attack Surface Management is another paid platform with a free trial and pricing based on confirmed external assets. Consider it when that asset-based pricing approach better suits your scope.
KELA Platform has a 30-day free trial with no commitment or payment details required, and a Cloud Attack Surface Management plan priced at 65000.00 USD per year on a 12-month contract for one seat. It suits readers evaluating a longer trial or a defined annual commitment.
Obscuryn starts at 150.00 USD per month for up to five monitored domains, email alerts and community support. Choose it when that stated domain allowance and price are a better fit.
Allure Brand Protection offers flat-rate pricing with no per-incident fees or takedown limits, with coverage varying by plan and organization needs; it is worth considering when those pricing terms matter most.
ZeroFox Attack Surface Intelligence uses tailored packages with pricing by quote.
Constella Hunter+ provides pricing by demo request.
Readers comparing category-wide options can also browse Digital Risk Protection Software and Dark Web Monitoring Services.
Verdict
PhishEye is a strong candidate for security, fraud and brand teams that need multi-signal impersonation monitoring tied to takedown workflows, particularly MSPs that can use its child workspaces. Its main advantages are broad signal coverage and operational options such as threat-feed export and Pro integrations. Look elsewhere if a one-time scan is not enough but custom-priced plans are a barrier, or if formal security certifications are a firm requirement.
PhishEye plans and pricing
All plansCompared on digital risk protection software
- Free plan
- Yes
