Highscore 40 · flagged Sunday, September 13, 2026

cafelaposte1.cafe

Appeared in the .cafe zone on Sunday, September 13, 2026; by the end of that day the census found boilerplate page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: laposte
+14
brand plus digits
matched: cafelaposte1
+8
brand name at a retail registrar
matched: GoDaddy.com, LLC
+8
identical page on many newborns
matched: 3088 identical pages
+10
Registrar
GoDaddy.com, LLC
Nameserver provider
Nameservers
ns19.domaincontrol.com, ns20.domaincontrol.com
First-day state
boilerplate page
HTTP status
200
Page title
Has a form
no
Brand echoed
laposte

Model opinions

First passsuspicioustarget: La Posteconfidence 65%· claude-haiku-4-5

Domain name combines 'cafe' with 'laposte' (French postal service) and includes digits (cafelaposte1), suggesting brand-squatting. The page currently displays an 'Access Denied' error attempting to fetch a dot-cafe.org article, which appears to be a placeholder or misconfiguration rather than active phishing content. The 3088-domain cluster and GoDaddy registration pattern are consistent with bulk phishing infrastructure, but no credential capture or impersonation page is currently visible—this

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, September 13, 2026

Screenshot of cafelaposte1.cafe taken by the zone census on 2026-09-13

Same data as JSON: /api/zone/domain/cafelaposte1.cafe. This page is not indexed by search engines and does not link to the site it describes.