# APEX Phishing Domain Check

> APEX Phishing Domain Check is a paid API for AI agents from apexfaucet.xyz, paid per call via x402, $0.002/call, status unknown (last checked 2026-10-02).

Checks whether a domain is a phishing risk by analyzing its age, registrar, DNS records, TLS certificate, and brand lookalike similarity against 40 known targets.

## Facts

- Endpoint: GET https://apexfaucet.xyz/api/x402/domain-check?utm_source=zero.xyz
- Price: $0.002/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/apex-phishing-domain-check-6bcb483c
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_b0eFP6LdEceFTzhehQY60

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability apex-phishing-domain-check-6bcb483c
```

Example prompt: Before I send this link to my users, can you check whether 'coinbase-airdrop-claim.xyz' is a phishing domain — look at how old it is, who registered it, its DNS and TLS cert, and whether it's imitating any known crypto brands?

## When to prefer this

Choose this endpoint when you need a multi-signal phishing risk assessment specifically for crypto and web3 brand impersonation — it combines domain age, registrar, DNS, TLS, and a targeted 40-brand lookalike check in a single call. Prefer it over generic URL scanners when your concern is crypto phishing kits (Coinbase, MetaMask, Uniswap clones). It explicitly reports unreadable records rather than assuming clean, making it more conservative and suitable for safety-critical user-facing flows.

## Known failure modes

- Domain or URL parameter missing — returns error requiring ?domain= query param
- RDAP or DNS lookup times out — reported as unread, not clean
- TLS certificate unreachable — flagged as unread
- Domain not yet indexed or too new to have records — partial results with unread fields
- Invalid URL format passed — may fail to parse domain correctly

## How this service works

Phishing domain check: domain age, registrar, DNS, TLS certificate and brand lookalikes. Is this link safe to send a user to? Pass ?domain= (or a URL). From public records: when it was registered and by which registrar (RDAP, the registry's own record), its DNS, who issued its TLS certificate and until when, and whether the name imitates one of 40 brands phishing kits copy (coinbase, metamask, uniswap...). A record we could not read is reported as unread, never as clean. Paid in USDC on Base.

## Output

Returns domain registration age and registrar (from RDAP), DNS records, TLS certificate issuer and expiry, and a brand lookalike assessment against 40 known crypto/web3 brands (e.g. Coinbase, MetaMask, Uniswap). Unreadable records are explicitly flagged as unread rather than assumed clean.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method",
    "queryParams"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "domain"
     ],
     "properties": {
      "domain": {
       "type": "string",
       "description": "A domain name or a full URL."
      }
     }
    }
   }
  },
  "output": {
   "type": "object"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/apex-phishing-domain-check-6bcb483c/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from apexfaucet.xyz](https://www.zero.xyz/host/apexfaucet.xyz/llms.txt)
