Highscore 55 · flagged Thursday, October 1, 2026

amazon-pt.click

Appeared in the .click zone on Thursday, October 1, 2026; by the end of that day the census found server error. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: amazon
+30
TLD with a high abuse rate
matched: click
+8
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: Devexpanse Ltd
+8
brand name and brand-styled page
matched: amazon
+15
Registrar
Devexpanse Ltd
Nameserver provider
Nameservers
coby.ns.cloudflare.com, teagan.ns.cloudflare.com
First-day state
server error
HTTP status
521
Page title
amazon-pt.click | 521: Web server is down
Has a form
no
Brand echoed
amazon

Model opinions

Second opinionlooks like abusetarget: Amazonconfidence 80%· claude-opus-5-5

The name pairs the distinctive Amazon brand with a Portugal country tag ('amazon-pt') on a cheap .click TLD through a retail registrar, a brand-squat Amazon would not run itself. The page only shows a Cloudflare 521 'web server is down' error, so no phishing content can be seen yet and the name is the deception.

First passsuspicioustarget: Amazonconfidence 65%· claude-haiku-4-5

The domain amazon-pt.click contains Amazon's brand name with a country code (PT = Portugal) and the .click TLD—a pattern consistent with phishing infrastructure. However, the page currently shows only a legitimate Cloudflare 521 error (web server down) with no phishing content, login form, or impersonation attempt visible. The registration via Devexpanse Ltd and use of Cloudflare nameservers raises concern, but without an active phishing page, this appears to be either a failed phishing deployme

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Thursday, October 1, 2026

Screenshot of amazon-pt.click taken by the zone census on 2026-10-01

Same data as JSON: /api/zone/domain/amazon-pt.click. This page is not indexed by search engines and does not link to the site it describes.