Netcraft
London's cybercrime-disruption service, detecting and taking down phishing and scam sites since 1994
Quick Overview
| Company | Netcraft Ltd |
|---|---|
| Category | Web Security |
| Headquarters | London, United Kingdom |
| Founded | 1994 |
| EU Presence | United Kingdom (adequacy decision, outside the EEA) |
| Open Source | No |
| Pricing | Enterprise pricing on request; no published price list |
| Free Option | Contact sales |
| Replaces | PhishLabs, ZeroFox, BrandShield |
Detailed Review
Netcraft is the oldest company in this directory by three decades, tracking web server usage since 1994 and building a digital risk protection platform on top of that history. The current product detects phishing sites, scam pages and brand-impersonating domains as they appear, and then acts on the detection: takedown requests go out to the hosting provider, registrar or platform involved, backed by relationships built over thirty years of doing exactly this.
The detection layer runs on AI models trained on Netcraft's own long-running internet telemetry, covering typosquatted domains, fake app store listings, fraudulent social media accounts and look-alike login pages — the categories of attack that target a brand's customers rather than its infrastructure, and that a CDN or WAF sitting in front of a website cannot see at all.
Netcraft Ltd is registered in England and Wales, based in London, so the customer and brand data it processes to run these detections sits under UK law with an EU adequacy decision rather than direct GDPR establishment. Pricing is not published; every engagement is quoted, which means evaluating cost requires a sales conversation. It is not a substitute for the CDN or WAF layer — it protects the brand's identity outside the site, not the site's infrastructure.
What Netcraft does well
- Three decades of internet threat-intelligence history
- Detects and takes down phishing, scams and impersonation
- Covers domains, apps and social media, not just websites
- AI-powered detection at internet scale
- Long-established relationships for fast takedowns
Where Netcraft falls short
- No published pricing — every deal is quoted
- UK jurisdiction, adequacy decision rather than EU establishment
- Protects brand identity, not site infrastructure
- Not a WAF, CDN or DDoS layer
Standout feature. Thirty years of takedown relationships — the reason a Netcraft phishing report gets acted on faster than a fresh vendor's would.
Pros and Cons
Pros
- Three decades of internet threat-intelligence history
- Detects and takes down phishing, scams and impersonation
- Covers domains, apps and social media, not just websites
- AI-powered detection at internet scale
- Long-established relationships for fast takedowns
Cons
- No published pricing — every deal is quoted
- UK jurisdiction, adequacy decision rather than EU establishment
- Protects brand identity, not site infrastructure
- Not a WAF, CDN or DDoS layer
Alternatives to Netcraft
Frequently Asked Questions
What is Netcraft?
Netcraft is the oldest company in this directory by three decades, tracking web server usage since 1994 and building a digital risk protection platform on top of that history. The current product detects phishing sites, scam pages and brand-impersonating domains as they appear, and then acts on the detection: takedown requests go out to the hosting provider, registrar or platform involved, backed by relationships built over thirty years of doing exactly this.
Where is Netcraft based?
Netcraft operates from London, United Kingdom, which places it under United Kingdom (adequacy decision, outside the EEA).
What does Netcraft cost?
Enterprise pricing on request; no published price list. Contact sales.
Who is Netcraft best for?
Brands needing phishing and scam takedown at internet scale. Thirty years of takedown relationships — the reason a Netcraft phishing report gets acted on faster than a fresh vendor's would.
What are the drawbacks of Netcraft?
No published pricing — every deal is quoted. UK jurisdiction, adequacy decision rather than EU establishment. Protects brand identity, not site infrastructure. Not a WAF, CDN or DDoS layer.