arrivalpaymentstatus.com
Appeared in the .com zone on Sunday, September 13, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name 'arrivalpaymentstatus' is a textbook parcel-delivery-fee smishing lure phrase, and the site serves no content of its own — it bounces visitors to google.com, a classic cloaking/dormant posture for an SMS campaign behind Cloudflare NS. All Google branding in the evidence belongs to the redirect destination, not this domain, so there is no impersonation yet to judge; the intent is strongly suggested but not demonstrated.
The domain name 'arrivalpaymentstatus.com' contains payment-related lure words and redirects to Google's homepage rather than serving its own content. This redirect-to-legitimate-brand behavior is consistent with a typosquat or intermediary setup that may be used to phish users by redirecting them onward after capturing data, or to establish reputation through redirect chains. The incongruence between the domain's implied purpose ('arrival payment status') and its redirect target (Google homepag
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Sunday, September 13, 2026

Same data as JSON: /api/zone/domain/arrivalpaymentstatus.com. This page is not indexed by search engines and does not link to the site it describes.