1santander-movil.com
Appeared in the .com zone on Saturday, October 10, 2026; by the end of that day the census found boilerplate page. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name '1santander-movil' squats on Santander's mobile banking product, with a digit prefix typical of phishing kits, and was registered at a retail registrar. The page is only a Tucows expired-domain parking page with Santander-themed search links ('Santander Movil Actualiza Tus Datos', 'Supermovil') and no form, so this is a brand-squat rather than active phishing.
This is a parked domain with a boilerplate expiration notice and search-suggestion template. The domain name contains 'santander' (the bank brand) but the page itself makes no impersonation attempt—it displays only a generic parking/expired-domain placeholder with search topics, not a phishing form or credential capture. The 717-domain cluster and brand+digits pattern indicate a typosquat/brand-squat campaign, but without active impersonation or deception content, this is brand-squat abuse, not
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Saturday, October 10, 2026

Same data as JSON: /api/zone/domain/1santander-movil.com. This page is not indexed by search engines and does not link to the site it describes.