ato-gov-au-login.cfd
Appeared in the .cfd zone on Thursday, October 8, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name 'ato-gov-au-login' on a cheap .cfd TLD spoofs the ATO's ato.gov.au sign-in, and its only plausible purpose is deception; it currently redirects to google.com, a common cloaking pattern for staged phishing. No ATO credential page is served yet, and the Google form belongs to the redirect target, not this domain.
The domain name 'ato-gov-au-login.cfd' impersonates the Australian Taxation Office by combining 'ato' (the ATO's acronym), 'gov-au' (Australian government domain structure), and 'login' to create a credential-harvesting lure. The redirect to Google Search is a common deception tactic: it legitimizes the domain to initial inspection while the attacker waits for victims to enter credentials via a form (the page shows an active form posting to www.google.com). The .cfd TLD, multiple hyphens, and 'g
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Thursday, October 8, 2026

Same data as JSON: /api/zone/domain/ato-gov-au-login.cfd. This page is not indexed by search engines and does not link to the site it describes.