Loading...
Loading...
Loading...
Comprueba URLs, dominios, IPs, correos y hashes de archivos contra fuentes seleccionadas de inteligencia de amenazas con una sola llamada HTTP. Acceso gratuito con límite de uso y licencias comerciales disponibles.
Free tier: 10 requests/minute and 100/day per IP, no signup.
$ curl -s https://scamatrix.com/api/v1/scan \
-d '{"input":"wallet-verify-login.example"}'
{
"result": true,
"type": "Domain",
"matches": [
{ "feed": "Phishing Database" },
{ "feed": "Stamparm Ipsum", "indicator": "203.0.113.24" }
],
"total_processing_time": 184
}Phishing, malware, C2 and scam indicators from vetted public and community sources, kept continuously up to date.
Domains are resolved to A, AAAA, CNAME and MX records, URLs and emails to their domains, IPs to reverse DNS. Every pivot is checked too.
No SDK to install. POST an indicator, get a verdict, the feeds that matched and everything we checked.
$0
Let's talk
Step 1
Send any indicator to the scan endpoint. No signup or key is needed for the free plan. ScaMatrix detects the type, checks it against every feed, follows DNS pivots and returns a JSON verdict.
curl -X POST https://scamatrix.com/api/v1/scan \
-H "Content-Type: application/json" \
-d '{"input": "http://wallet-verify-login.example/signin"}'
# Licensed plan: add your key
# -H "X-API-Key: $SCAMATRIX_API_KEY"
# Quick GET for a single indicator
curl "https://scamatrix.com/api/v1/scan?input=203.0.113.24"Access
Free plan
No header. Requests are counted per client IP. Intended for personal, research and non-commercial use.
Licensed plan
Send X-API-Key: your-key on every request. Keep the key on your server, never in browser code.
Reference
POSThttps://scamatrix.com/api/v1/scan
GEThttps://scamatrix.com/api/v1/scan?input=<indicator>
POST a JSON body with Content-Type: application/json, or use GET with a query string for a single indicator.
| Field | Type | Required | Description |
|---|---|---|---|
| input | string | Yes* | The indicator to scan: URL (with http/https), domain, IPv4/IPv6, email address, or MD5/SHA1/SHA256 hash. Type is detected automatically. Alias: indicator. |
| iocs | string[] | No | Scan up to 10 indicators in one request (for example the three hashes of a file). When set, input is only used as a display label. |
* Either input or iocs. Each value can be up to 2048 characters.
Copy & paste
curl -X POST https://scamatrix.com/api/v1/scan \
-H "Content-Type: application/json" \
-d '{"input": "http://wallet-verify-login.example/signin"}'
# Licensed plan: add your key
# -H "X-API-Key: $SCAMATRIX_API_KEY"
# Quick GET for a single indicator
curl "https://scamatrix.com/api/v1/scan?input=203.0.113.24"Reference
A malicious verdict for a domain: the domain itself is on a phishing list and one of its A records is on an IP reputation list. Example values use reserved documentation names.
{
"indicator": "wallet-verify-login.example",
"normalized_indicator": "wallet-verify-login.example",
"result": true,
"type": "Domain",
"total_processing_time": 184,
"matches": [
{
"feed": "Phishing Database",
"indicator": "wallet-verify-login.example",
"indicatorType": "domain",
"source": "Phishing Database"
},
{
"feed": "Stamparm Ipsum",
"indicator": "203.0.113.24",
"indicatorType": "ip",
"source": "Stamparm Ipsum"
}
],
"alternative_indicators": [
{
"label": "IPv4 (A Record)",
"indicators": [{ "value": "203.0.113.24", "tagged": true }]
},
{
"label": "Domain (MX Record)",
"indicators": [{ "value": "mx.wallet-verify-login.example", "tagged": false }]
}
],
"feed_summary": {
"statuses": [
{ "name": "Phishing Database", "status": "ok", "matched": true },
{ "name": "ThreatFox", "status": "ok", "matched": false }
]
},
"last_updated": "2026-10-01T12:00:00.000Z"
}resultboolean
true when the indicator, or anything it resolves to, appears in at least one feed.
typestring
Detected indicator type: URL, Domain, IPv4, IPv6, Email, MD5, SHA1, SHA256, or Multiple Indicators.
normalized_indicatorstring
The value that was actually looked up (lowercased, trimmed).
matches[]object[]
One entry per feed hit: feed name, the matching indicator (primary or pivoted), and its indicatorType.
alternative_indicators[]object[]
Pivots ScaMatrix checked for you: A/AAAA, CNAME and MX records, reverse DNS, or the domain of a URL or email. tagged marks the ones that matched.
mx_missing[]string[]
Domains (scanned or from an email) that publish no usable MX record, including a null MX. Such domains cannot receive mail.
feed_summary.statuses[]object[]
Every feed checked for the scanned types, with matched: true for feeds that flagged it.
total_processing_timenumber
Server-side time in milliseconds.
last_updatedstring
ISO 8601 timestamp of the response.
Guide
Send up to 10 values in iocs and they are scanned together as one request (one unit against your rate limit). A common use is checking all three hashes of a file:
curl -X POST https://scamatrix.com/api/v1/scan \
-H "Content-Type: application/json" \
-d '{
"input": "invoice.pdf",
"iocs": [
"44d88612fea8a8f36de82e1278abb02f",
"3395856ce81f2b7382dee72602f798b642f14140",
"275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f"
]
}'Fair use
Free · per IP
10 / minute
100 / day
Licensed · per key
120+ / minute
20,000+ / day
Every request counts, including ones that return 400. The ScaMatrix website uses the same limits. Each response tells you where you stand:
| X-RateLimit-Plan | free or licensed. |
| X-RateLimit-Limit | Requests allowed in the window that is closest to running out. |
| X-RateLimit-Remaining | Requests left in that window. |
| X-RateLimit-Reset | Unix time (seconds) when that window resets. |
| Retry-After | Sent with 429 and 202 responses: seconds to wait before retrying. |
Cache results on your side, back off when you get 429, and don't rotate IPs to get around the free limits. Abusive traffic may be blocked.
Reference
OK
Scan completed. Check result and matches.
Preloading
Threat feeds are still loading after maintenance. Retry after the Retry-After header (seconds).
Bad request
Missing input, unknown indicator type, value over 2048 characters, or more than 10 iocs.
Invalid API key
The X-API-Key header was sent but is not a valid license key. Omit it to use the free plan.
Rate limited
You hit a per-minute or per-day limit. Wait for Retry-After seconds, or contact us for a license.
Server error
Something failed on our side. Retry with backoff; contact support if it persists.
Error bodies are JSON with an error message.
Commercial use
Using the API in a commercial product, service or internal business workflow requires a license. Email us with your company, use case and expected volume, and we'll set you up with an API key and limits that fit.
Results come from third-party feeds and may contain false positives or miss new threats. Use of the API is subject to the ScaMatrix terms.