One submission, the whole story. The Sandbox visits the URL like a real browser and records everything a security team needs to investigate and document with confidence.
Full-page screenshot and complete DOM content: see exactly what a victim would see, and search the underlying markup for kit artifacts.
SSL certificates, every resolved domain, and server details: the infrastructure fingerprint that connects one scan to a wider campaign.
Detected technologies, cookies, loaded resources, and link/script tags: everything the page pulled in, and from where.
Heuristic-weighted scoring surfaces suspicious indicators immediately, so analysts can triage at a glance and spend their time on what actually looks dangerous.
Every scan produces a permanent report at /report/<id>.
Share findings with teammates, takedown providers, or clients with a single link.
Submit scans from the console for hands-on investigation, or drive the Sandbox programmatically through the API, feeding suspicious URLs in from your SOAR, abuse inbox, or detection pipeline.
On Research Lab and above, Private Scans keep sensitive investigations out of public view.
100 free scans a day on the Starter plan
Full evidence capture with a shareable report for every scan
Scale to tens of thousands of scans daily by API