Skip to content
Cybersecurity & Trust · Use case

See the phishing page your customers see, not the one it shows your scanner

Verify suspect domains and links from real residential and mobile IPs, in the victim's country, so cloaked kits have nowhere to hide.

Failed requests freeTraffic never expires24-hour refund on unused plans
Verification queueIllustrative values

See what the victim sees. The scanner never does.

Key takeaway

Email and domain verification checks need to reach sign-up pages, MX records and landing pages the way a real user does. Residential proxies carry your own checker; the Unlocker API returns each page as data. Failed requests are free.

Why email & domain verification is hard to do at scale

Email authentication protects the domain you own. SPF, DKIM and DMARC will bounce a message that forges your address. They do nothing about the domain an attacker registered yesterday that looks almost like yours, signs its own mail cleanly, and passes every check a receiving server runs.

Blocklists are reactive by design: a site has to be found and reported before it is flagged. In one 2026 test a major safe-browsing service missed roughly 84% of confirmed phishing sites. The gap is the window in which the attack works.

And the sites themselves hide. Phishing kits cloak: a security scanner from a datacenter IP sees a blank page or a redirect to the real brand, while a victim on a home connection in the targeted country sees the credential form. To detect the kit you have to look like the victim.

How Datafuel handles email & domain verification

Datafuel's residential and mobile networks let your verification tooling arrive at a suspect page the way a target would: from a home or carrier IP, in the right country, on the right device type. Cloaking that keys on IP reputation or geography stops working.

The Unlocker API fetches and renders suspect pages at scale, returning the content your classifier needs. Datacenter proxies handle the high-volume top of the funnel: DNS resolution, WHOIS lookups and lookalike-domain sweeps across thousands of registrations, where a clean fast IP is what matters.

Where authentication stopsIllustrative values
Two paths

Keep your collector and fix the network, or hand us the URL. Same IPs, same billing rule.

Residential proxiesUnlocker API
You bringyour own scraper and parsera URL, and a schema if you want JSON
You getthe raw page from a local residential IPMarkdown or structured JSON, past any protection
Targetingcountry · region · city · ASN · OScountry and city, per request
CAPTCHAshandled by your scraperhandled inside the request
Billingper GB, traffic never expiresper successful request, credits never expire
Best whenyou already run a working scraperyou want pages without maintaining a parser

Many teams use both: the API for the pages that block, proxies for the collectors they already run.

Products for email & domain verification

Same price on every use case. Failed requests are free and purchased traffic never expires.

If you run your own checkerResidential Proxieswas $4.50, now $3.15 $4.50per GB46M+ consent-based household IPs, 195+ countries, city and ASN targeting.
  • 46M+ consent-based household IPs
  • Rotating or sticky up to 24h
  • Region, city, ASN targeting
  • HTTP(S) & SOCKS5
  • Traffic never expires
If you want the page as dataUnlocker APIwas $0.042, now $0.029 $0.042per 1KAny page past any protection, returned as Markdown or structured JSON.
  • Any page past any protection
  • CAPTCHAs handled inside the request
  • Markdown, JSON, HTML or screenshot
  • Failed requests are free
  • MCP ready

How it works

  1. 01Feed suspect domains and URLs from your mail gateway, threat intelligence or lookalike monitoring.
  2. 02Datafuel fetches each one from a residential or mobile IP in the targeted country, rendering the page as a victim would see it.
  3. 03Content, screenshots and redirects return to your classifier for verdict and takedown.
Try it on your own targets. Failed requests are free.Start free

What to watch for

  • Verification traffic touches malicious infrastructure. Isolate it from your production network and never submit real credentials.
  • Attackers rotate fast. Verify at first sight, not on a daily batch; a kit can live for hours.
  • Keep a record of what you fetched and when. Takedown requests and evidence chains depend on it.

Email & domain verification — frequently asked questions

Why not verify from our own IPs?
Because kits cloak on IP reputation and location. Your corporate range is exactly what they filter for.
Can I choose the country and device type?
Yes. Country, region, city and OS on residential; carrier (by ASN) on mobile.
Do you provide screenshots?
Yes, via the Unlocker API, alongside rendered content and the redirect chain.
Can this run at high volume?
Yes. Datacenter proxies cover sweeps across thousands of domains; residential and mobile cover the smaller set that needs a victim's-eye view.
Is this an acceptable use of your network?
Security research and verification are supported uses. Our acceptable use policy sets out the boundaries.
Sources. Figures on this page come from 2026 reports by Cloudflare, HUMAN Security, Neudata, PromptCloud, Nasdaq, Forrester, MarqVision, Bitsight and Kadoa.Last updated .
Get started

Ready to build?

Start with the free tier and scale as your project grows. No credit card, no sales call.

Talk to an engineer, not a chatbot.