Phishing Blocker
Phishing detection is a Bitwarden feature that reviews trusted databases for malicious websites with known connections to phishing attacks. Phishing detection utilizes the open source Phishing.Database to identify and warn users when they visit a website that could put their credentials at risk.
The Phishing detection feature is available for Bitwarden premium users on browser clients 2025.9.0 and newer.
When the Bitwarden phishing detection feature identifies a known phishing website:
- Instead of loading a known phishing website, Bitwarden will redirect the user to a notification page, indicating that the site has been blocked.  - Phishing website blocked 
- Select the appropriate option: - Close tab: Selecting this option will close out the malicious tab that Bitwarden has blocked. 
- Continue: Selecting this option will allow you to continue to the website and close the Bitwarden phishing blocker. - warning- Selecting Continue will proceed to the website that was identified for previous phishing activity. This action could result in your credentials being compromised. Caution is recommended if selecting this option. 
 
Self hosted deployments will be required to enable the following settings in bwdata/env/global.override.env in order for Bitwarden to communicate with the cloud database:
Plain TextglobalSettings__selfHosted = true globalSettings__enableCloudCommnunication = true
Bitwarden phishing detection uses the phishing database to reference known phishing sites. This open source tool is updated daily by users to identify harmful URLs.
- Phishing detection provides sets of lists that can be accessed via clicking on the list, or accessing with the back end. 
- The Bitwarden API fetches the list and saves the list to Azure Block Storage. 
- The Bitwarden API uses the SHA-256 checksum to identify changes in the list and fetch updated lists. 
- Using the browser extension, Bitwarden will check URLS against the phishing list on page load. 
- If the site is a match with a known threat on the phishing database, Bitwarden will take you to a blocked screen, providing the options to leave the site or continue.