Highscore 51 · flagged Tuesday, September 8, 2026

56ckcclk0rder7382847283.cfd

Appeared in the .cfd zone on Tuesday, September 8, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

random-looking name
matched: H=3.68
+5
TLD with a high abuse rate
matched: cfd
+8
brand in page title, not in the name
matched: google
+20
form on a brand-styled page
matched: has_form
+18
Registrar
Global Domain Group LLC
Nameserver provider
Nameservers
alexa.ns.cloudflare.com, vick.ns.cloudflare.com
First-day state
redirects elsewhere
HTTP status
200
Page title
Google
Has a form
yes
Brand echoed

Model opinions

Second opinionsuspiciousconfidence 70%· claude-opus-5

The domain serves no content of its own — it 302s crawlers to www.google.com, the classic cloaking fallback of SMS/email lure campaigns; the name itself is a high-entropy DGA-style string embedding an obfuscated 'ckcclk'/'0rder' token plus a fake order number, on a .cfd throwaway TLD behind Cloudflare NS. Google's own page is the redirect destination, so there is no impersonation to judge here, but the name and cloaking pattern strongly suggest a pending order/parcel-themed lure rather than legi

First passlooks like abuseconfidence 92%· claude-haiku-4-5

The domain name '56ckcclk0rder7382847283.cfd' exhibits DGA-shape characteristics (random alphanumeric string with numbers appended) and uses the suspicious .cfd TLD. It redirects to Google's legitimate homepage, which is consistent with a typosquat or redirect-farming abuse pattern rather than active phishing. The domain itself does not host a credential-capture page; it merely redirects to Google's real site, making it abuse (squat/redirect spam) rather than phishing.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Tuesday, September 8, 2026

Screenshot of 56ckcclk0rder7382847283.cfd taken by the zone census on 2026-09-08

Same data as JSON: /api/zone/domain/56ckcclk0rder7382847283.cfd. This page is not indexed by search engines and does not link to the site it describes.