56ckcclk0rder7382847283.cfd
Appeared in the .cfd zone on Tuesday, September 8, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The domain serves no content of its own — it 302s crawlers to www.google.com, the classic cloaking fallback of SMS/email lure campaigns; the name itself is a high-entropy DGA-style string embedding an obfuscated 'ckcclk'/'0rder' token plus a fake order number, on a .cfd throwaway TLD behind Cloudflare NS. Google's own page is the redirect destination, so there is no impersonation to judge here, but the name and cloaking pattern strongly suggest a pending order/parcel-themed lure rather than legi
The domain name '56ckcclk0rder7382847283.cfd' exhibits DGA-shape characteristics (random alphanumeric string with numbers appended) and uses the suspicious .cfd TLD. It redirects to Google's legitimate homepage, which is consistent with a typosquat or redirect-farming abuse pattern rather than active phishing. The domain itself does not host a credential-capture page; it merely redirects to Google's real site, making it abuse (squat/redirect spam) rather than phishing.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Tuesday, September 8, 2026

Same data as JSON: /api/zone/domain/56ckcclk0rder7382847283.cfd. This page is not indexed by search engines and does not link to the site it describes.