bookbindersdesign.team
Appeared in the .team zone on Sunday, October 4, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The domain is gated by a real Cloudflare Access login on the team's own cloudflareaccess.com subdomain. The signed JWT names hostname bookbindersdesign.team and the app is 'bookbinders-labels' on Cloudflare Workers, which is a standard Zero Trust setup by a small design business, not impersonation. Cloudflare branding here is the provider's own login page, and the email-only one-time-code form posts to Cloudflare itself.
The domain bookbindersdesign.team redirects to a Cloudflare Access login page that impersonates Cloudflare's authentication interface. The page displays the Cloudflare Access logo and branding, claims to be logging into 'bookbinders-labels - Cloudflare Workers', and presents a credential-harvesting form (email field with 'Send login code' button) that posts to the attacker-controlled Cloudflare Access subdomain. This is a sealed-room phishing attack using Cloudflare's own infrastructure against
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
Same data as JSON: /api/zone/domain/bookbindersdesign.team. This page is not indexed by search engines and does not link to the site it describes.