Machine Learning-Based Classification of Phishing Websites Using URL and Domain Features
Keywords:
Phishing Detection, Malicious URLs, Machine Learning, Cybersecurity, URL Features, Domain Features, Website ClassificationAbstract
Phishing websites imitate trusted services to obtain credentials, financial information, or other sensitive data. Blacklists cannot reliably recognize newly created URLs, whereas content-based systems may require page retrieval, rendering, or third-party queries that add latency, exposure, and reproducibility concerns. This paper proposes a lightweight conceptual framework that classifies a URL before visiting its webpage by using 16 interpretable lexical and domain-related features. The framework covers data cleaning, duplicate removal, feature extraction, leakage-controlled splitting, model fitting, evaluation, and feature interpretation. A reproducible proof-of-concept simulation uses the open PhiUSIIL v2 URL corpus, with only its raw URL and label fields. After removing 425 exact duplicate URLs, 235,370 records were split 80:20 with stratification and a fixed seed. Logistic Regression, a depth-limited Decision Tree, and a depth-limited Random Forest were evaluated without exhaustive tuning. On the 47,074-record test set, Random Forest obtained accuracy 0.995943, precision 0.999098, recall 0.991395, F1-score 0.995231, specificity 0.999333, and ROC-AUC 0.998037. These values establish feasibility on this particular random split, not universal detection capability. The contribution is an auditable baseline linking simple Python feature extraction to conventional classifiers and deployment-oriented metrics. Major limitations include possible domain-family overlap, dataset-specific artifacts, temporal drift, and omission of webpage, certificate, redirection, and behavioral evidence.
References
L. Tang and Q. H. Mahmoud, ‘A survey of machine learning-based solutions for phishing website detection,’ Mach. Learn. Knowl. Extr., vol. 3, no. 3, pp. 672–694, 2021, doi: 10.3390/make3030034.
S. Asiri, Y. Xiao, S. Alzahrani, S. Li, and T. Li, ‘A survey of intelligent detection designs of HTML URL phishing attacks,’ IEEE Access, vol. 11, pp. 6421–6443, 2023, doi: 10.1109/ACCESS.2023.3237798.
J. S. Tharani and N. A. G. Arachchilage, ‘Understanding phishers’ strategies of mimicking uniform resource locators to leverage phishing attacks: A machine learning approach,’ Security and Privacy, vol. 3, no. 5, Art. no. e120, 2020, doi: 10.1002/spy2.120.
H. Le, Q. Pham, D. Sahoo, and S. C. H. Hoi, ‘URLNet: Learning a URL representation with deep learning for malicious URL detection,’ arXiv:1802.03162, 2018.
A. Hannousse and S. Yahiouche, ‘Towards benchmark datasets for machine learning based website phishing detection: An experimental study,’ Eng. Appl. Artif. Intell., vol. 104, Art. no. 104347, 2021, doi: 10.1016/j.engappai.2021.104347.
A. Safi and S. Singh, ‘A systematic literature review on phishing website detection techniques,’ J. King Saud Univ. Comput. Inf. Sci., vol. 35, pp. 590–611, 2023, doi: 10.1016/j.jksuci.2023.01.004.
M. Sameen, K. Han, and S. O. Hwang, ‘PhishHaven—An efficient real-time AI phishing URLs detection system,’ IEEE Access, vol. 8, pp. 83425–83443, 2020, doi: 10.1109/ACCESS.2020.2991403.
Y. A. Alsariera, V. E. Adeyemo, A. O. Balogun, and A. K. Alazzawi, ‘AI meta-learners and Extra-Trees algorithm for the detection of phishing websites,’ IEEE Access, vol. 8, pp. 142532–142542, 2020, doi: 10.1109/ACCESS.2020.3013699.
M. Al-Sarem et al., ‘An optimized stacking ensemble model for phishing websites detection,’ Electronics, vol. 10, no. 11, Art. no. 1285, 2021, doi: 10.3390/electronics10111285.
A. Taha, ‘Intelligent ensemble learning approach for phishing website detection based on weighted soft voting,’ Mathematics, vol. 9, no. 21, Art. no. 2799, 2021, doi: 10.3390/math9212799.
A. Aljofey et al., ‘An effective detection approach for phishing websites using URL and HTML features,’ Sci. Rep., vol. 12, Art. no. 8842, 2022, doi: 10.1038/s41598-022-10841-5.
M. Sánchez-Paniagua, E. F. Fernández, E. Alegre, W. Al-Nabki, and V. González-Castro, ‘Phishing URL detection: A real-case scenario through login URLs,’ IEEE Access, vol. 10, pp. 42949–42960, 2022, doi: 10.1109/ACCESS.2022.3168681.
S. Alnemari and M. Alshammari, ‘Detecting phishing domains using machine learning,’ Appl. Sci., vol. 13, no. 8, Art. no. 4649, 2023, doi: 10.3390/app13084649.
S. Kapan and E. S. Gunal, ‘Improved phishing attack detection with machine learning: A comprehensive evaluation of classifiers and features,’ Appl. Sci., vol. 13, no. 24, Art. no. 13269, 2023, doi: 10.3390/app132413269.
S. R. Abdul Samad et al., ‘Analysis of the performance impact of fine-tuned machine learning model for phishing URL detection,’ Electronics, vol. 12, no. 7, Art. no. 1642, 2023, doi: 10.3390/electronics12071642.
R. Yang, K. Zheng, B. Wu, C. Wu, and X. Wang, ‘Phishing website detection based on deep convolutional neural network and Random Forest ensemble learning,’ Sensors, vol. 21, no. 24, Art. no. 8281, 2021, doi: 10.3390/s21248281.
A. Ejaz, A. N. Mian, and S. Manzoor, ‘Life-long phishing attack detection using continual learning,’ Sci. Rep., vol. 13, Art. no. 11488, 2023, doi: 10.1038/s41598-023-37552-9.
V. Vajrobol, B. B. Gupta, and A. Gaurav, ‘Mutual information based logistic regression for phishing URL detection,’ Cyber Security Appl., vol. 2, Art. no. 100044, 2024, doi: 10.1016/j.csa.2024.100044.
K. S. Jishnu and B. Arthi, ‘Real-time phishing URL detection framework using knowledge distilled ELECTRA,’ Automatika, vol. 65, no. 4, pp. 1621–1639, 2024, doi: 10.1080/00051144.2024.2415797.
M. Elsadig et al., ‘Intelligent deep machine learning cyber phishing URL detection based on BERT features extraction,’ Electronics, vol. 11, no. 22, Art. no. 3647, 2022, doi: 10.3390/electronics11223647.
A. U. Rehman, I. Imtiaz, S. Javaid, and M. Muslih, ‘Real-time phishing URL detection using machine learning,’ Eng. Proc., vol. 107, no. 1, Art. no. 108, 2025, doi: 10.3390/engproc2025107108.
A. Rawla, S. Singh, M. Daniyal, and P. Dubey, ‘Detection of phishing attacks in PhiUSIIL dataset using deep learning,’ Procedia Comput. Sci., vol. 259, pp. 543–552, 2025, doi: 10.1016/j.procs.2025.04.003.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 The Author(s)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.