When to use this

Use this when a URL is not obviously clean or malicious but needs a recorded security decision.

How Verifence evaluates it

Phishing Submissions creates a review record for a suspicious URL; it is not an instant automated verdict. The URL is canonicalized, stored as pending, attributed to the submitting user, and sent to the review workflow so confirmed threats can later strengthen Verifence URL data.

Canonical submission

The submitted URL is normalized before storage so equivalent URL variants are less likely to create duplicate records.

Pending review

New submissions begin with a pending status rather than being treated as confirmed malicious immediately.

Reviewer notification

The application notifies the administrative review channel when a new suspicious link is submitted.

Threat-data feedback

A reviewed and activated submission can become part of the bad-URL data used by later URL scans.

How to do it

  1. 01 Run URL Scanning first when you need an immediate check against known threat data.
  2. 02 Open Phishing Submissions and enter the complete suspicious destination; Verifence canonicalizes it before storage.
  3. 03 Preserve the customer report, message text, screenshots, sender, and discovery source in your own case record so reviewers retain the surrounding evidence.
  4. 04 Treat the new submission as pending and keep any local quarantine in place until a review decision is available.
  5. 05 Use a confirmed, activated result as shared threat intelligence for later scans; do not treat submission alone as confirmation.

How to act on the result

Submit

Use the review flow when context suggests abuse but automated reputation does not provide enough certainty.

Keep blocked locally

If the link is already dangerous in your environment, quarantine it while the shared review is pending.

Confirm after review

Treat the review status—not the act of submission—as the authoritative shared classification.

Implementation notes

  • Include the complete destination and preserve the surrounding message, sender, and discovery source in your own incident record.
  • For an immediate known-threat check, run URL Scanning before or alongside the manual submission workflow.