allpay.group
Appeared in the .group zone on Saturday, September 19, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
allpay.group simply redirects to allpay.to, a consistently self-branded 'allpay' payment portal that also links to allpay.co.il — a defensive/companion registration of the same brand rather than impersonation; the 'allpay≈alipay' typo heuristic is a false positive since no Alipay branding, colours or product language appear anywhere.
The domain allpay.group uses a typosquat of 'Alipay' (allpay≈alipay) and redirects to allpay.to, which displays an 'allpay' branded login page with email/phone/Telegram sign-in tabs and 'Sign in with Google' button. The nameservers (alltrades.site) are unrelated to any legitimate Alipay infrastructure. The presence of Telegram and WhatsApp operator contact links, combined with the credential-capture form and offsite redirect chain, matches the phishing campaign pattern of impersonating a payment
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Saturday, September 19, 2026

Same data as JSON: /api/zone/domain/allpay.group. This page is not indexed by search engines and does not link to the site it describes.