Highscore 55 · flagged Wednesday, September 2, 2026

auth-paypal-secure.com

Appeared in the .com zone on Wednesday, September 2, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: paypal
+30
lure words (login, verify, secure…)
matched: auth,secure
+32
brand name at a retail registrar
matched: NameSilo, LLC
+8
brand name at a watch-list registrar
matched: NameSilo, LLC
+6
form on a brand-styled page
matched: has_form
+18
brand name redirects elsewhere
matched: gouv.fr
+8
Registrar
NameSilo, LLC
Nameserver provider
Nameservers
ns1.openprovider.nl, ns2.openprovider.be, ns3.openprovider.eu
First-day state
redirects elsewhere
HTTP status
200
Page title
Accueil impots.gouv.fr | impots.gouv.fr
Has a form
yes
Brand echoed
paypal

Model opinions

Second opinionlooks like abusetarget: PayPalconfidence 76%· claude-opus-5

auth-paypal-secure.com is a textbook PayPal brand-squat combining the brand with 'auth' and 'secure' lure words, registered at a retail registrar; it serves no content of its own and currently redirects to the unrelated French tax portal impots.gouv.fr, a typical cloaking/parking placeholder while the phishing kit is staged. No deceptive page is being shown yet, so this is brand-squat abuse rather than confirmed phishing.

First passlooks like phishingtarget: PayPalconfidence 95%· claude-haiku-4-5

Domain name 'auth-paypal-secure.com' directly impersonates PayPal with authentication and security lures. The redirect to the French tax authority (impots.gouv.fr) is a misdirection tactic; the domain itself is a credential-harvesting front designed to deceive visitors into believing they are accessing PayPal's authentication portal. The combination of PayPal branding in the domain name with lure words ('auth', 'secure') and use of a retail registrar (NameSilo) is characteristic of phishing infr

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Wednesday, September 2, 2026

Screenshot of auth-paypal-secure.com taken by the zone census on 2026-09-02

Same data as JSON: /api/zone/domain/auth-paypal-secure.com. This page is not indexed by search engines and does not link to the site it describes.