How do I verify a payment endpoint (URL) isn't a phishing site before paying?
Address screening cannot catch a spoofed endpoint: the payee address a fake site hands you is freshly generated and clean, so no address list has ever seen it. The catch has to happen at the domain layer — run the payment page or API URL against a malicious-domain corpus first. OceanAlt offers this free: GET oceanalt.com/api/endpoint?url=… matches more than 870,000 malicious domains (phishing databases, ScamSniffer, MetaMask and other feeds) and returns the source and listing date on a hit. The web version sits right on the address-check page.
What this scam looks like
The attacker clones an entry point you trust: a checkout page, an x402 paid API, a "new payment link" from support. Everything looks normal except the payee address, swapped for one generated minutes ago. Screen only the address and the best you get is "new address, insufficient history" — it genuinely has no record, because it barely exists.
Agents make it starker: an AI agent gets a URL first and takes the payee address from whatever that URL returns. When the endpoint is spoofed, no address list will ever object. This layer has to be checked on its own.
How to check
Web: open oceanalt.com/en/check and paste the URL into the endpoint box lower on the page. API: GET oceanalt.com/api/endpoint?url=https://pay.example.com, free and keyless, returns whether it hit, which database, and when it was listed.
Keep the old habits too: instead of clicking the link you were sent, reopen the site from an official channel and compare the domain spelling; before a large payment, send a small test amount first.
The boundary
A miss only means the domain is not in the known-malicious corpus yet. Newly registered phishing domains take time to get listed, and the fresher the scam the wider that window. Domain age, certificates and spelling similarity help, but none of them settles it.
Where to start: free address check · API docs · watch an address
Boundary of everything above: a screening "clear" only means no match in the data held, never a safety guarantee; this page is not legal or compliance advice.

