Lookyloo VPS — from €5.49/mo

Investigate websites and web threats on your own server — Lookyloo on NVMe with a 5-hour test period, so you risk nothing

Launch Lookyloo now
A virtual server for Lookyloo

A Lookyloo VPS is a virtual server with full root access for investigating websites and web threats. You install Linux, Docker and the Lookyloo stack yourself to capture redirect chains, page resources and the behaviour of suspicious pages in an isolated environment. The analysis runs on a server with headless browsers instead of your own PC, and NVMe storage keeps captures and logs close at hand. Plans start at €5.49/mo with a 5-hour test period — verify the tool on your own cases before paying.

Plans

A VPS for Lookyloo

Occasional checks fit into Standard 1 (4 vCPU, 4 GB); for regular work take Standard 2 (4 vCPU, 6 GB). For a steady stream of captures and a snapshot archive go with Standard 4 (8 vCPU, 8 GB, 100 GB NVMe) or higher. 5-hour test period before payment.

Compare all plans
5.49 mo

Standard 1

4 vCPU · AMD EPYC
4 GB RAM
50 GB NVMe
Unlimited traffic
IPv4 · KVM
24/7 support
6.99 mo

Standard 2

4 vCPU · AMD EPYC
6 GB RAM
60 GB NVMe
Unlimited traffic
IPv4 · KVM
24/7 support
1

Your own Lookyloo stack

Install Docker and Lookyloo with headless browsers — record redirects, resources and page behaviour the way your workflow needs.

2

Analysis in isolation

Suspicious sites open on the server, not on your PC — the investigation runs around the clock in a separate environment.

3

Captures on NVMe

Fast storage and spare RAM keep page captures, screenshots and logs close, speeding up incident analysis.

How to run Lookyloo on a VPS

1

Pick a plan and an image

Choose a plan — Standard 1 (4 vCPU, 4 GB) or Standard 2 (4 vCPU, 6 GB) — and select a Linux image, Ubuntu or Debian, for your analysis stack.

2

Install the OS yourself

Through the panel you deploy the chosen OS on the KVM server yourself — the environment stays under your full control.

3

Set up Lookyloo

Over SSH or the KVM console install Docker and Lookyloo, start the service and open the analysis dashboard from your browser.

A server for threat research

A server for threat research

We will help you size the plan by the number of checks and the capture volume: RAM, vCPU count and NVMe space for screenshots and logs.

We can also help with Docker and an isolated setup. Related topics are covered on the Docker VPS page and the security and VPN overview.

Get sizing advice

Frequently asked questions

Didn't find your answer?
Write to us via the contact page.

For website analysis: it records redirect chains, resources and page behaviour — useful when investigating phishing and web threats.

Suspicious pages open in an isolated environment on the VPS instead of your own PC — a much safer way to examine threats.

Each capture starts its own browser instance and takes 1–2 GB of RAM, so concurrency is limited by the plan's memory. 8 GB comfortably handles 2–3 captures.

Yes. Once Lookyloo is running, the web dashboard opens at the server's address — you analyse captures remotely.

The tool launches browsers and stores session snapshots: take at least 8 vCPU and 8 GB (Standard 4, €10.99/mo) and keep an eye on disk space.

Every capture stores HTML, resources and screenshots — it adds up to gigabytes quickly. For active use take at least 160 GB NVMe (Power 1, €17.99).

Yes, publish the interface behind Nginx with authentication and TLS. Do not leave it open without a password — it exposes your whole research archive.

Yes, you can mount your own installation image through the KVM console. There are no distro restrictions — you have full access to the server.