0rder-accept.cfd
Appeared in the .cfd zone on Saturday, September 26, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The domain redirects offsite to the real www.google.com, so the Google page and its search form are not impersonation by this domain. The name '0rder-accept' uses a zero for the 'O' and order-confirmation lure wording, sits on a throwaway .cfd TLD behind Cloudflare, and a redirect to Google is a common cloaking pattern that hides a scam page from scanners, but no deceptive content has been served yet.
typesafe first pass (gate 0.4): p=benign:0.64 suspicious:0.25 abuse:0.05 | impersonates=0.22 credential=0.57 parked=0.58 evidence=1.2 | target=none:0.72
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Saturday, September 26, 2026

Same data as JSON: /api/zone/domain/0rder-accept.cfd. This page is not indexed by search engines and does not link to the site it describes.