Highscore 55 · flagged Thursday, September 10, 2026

chrome-authenticator.com

Appeared in the .com zone on Thursday, September 10, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: authenticator
+30
free DNS provider
matched: dnsowl.com
+8
brand name at a retail registrar
matched: NameSilo, LLC
+8
brand name at a watch-list registrar
matched: NameSilo, LLC
+6
brand in page title, not in the name
matched: google
+20
form on a brand-styled page
matched: has_form
+18
brand name redirects elsewhere
matched: google.com
+8
Registrar
NameSilo, LLC
Nameserver provider
Nameservers
ns1.dnsowl.com, ns2.dnsowl.com, ns3.dnsowl.com
First-day state
redirects elsewhere
HTTP status
200
Page title
Google
Has a form
yes
Brand echoed
authenticator

Model opinions

Second opinionlooks like abusetarget: Googleconfidence 70%· claude-opus-5

The name combines Google's Chrome trademark with 'authenticator', a classic 2FA/credential lure, and serves no content of its own — it simply 302s to the real www.google.com, a common aging/cloaking pattern for a brand-squat registered on a cheap retail registrar (NameSilo) with free DNS (dnsowl). No deceptive page is served yet, so this is a Google brand-squat awaiting weaponisation rather than an active phish.

First passlooks like phishingtarget: Googleconfidence 95%· claude-haiku-4-5

The domain chrome-authenticator.com is a clear typosquat designed to impersonate Google's authenticator product. It redirects to google.com, but the domain name itself—combining 'chrome' (Google's browser) and 'authenticator' (Google's 2FA tool)—is crafted to deceive users seeking Google's authentication services into visiting a attacker-controlled domain. The use of free DNS (dnsowl.com) and NameSilo registrar are typical of phishing infrastructure. The redirect to the legitimate Google homepag

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Thursday, September 10, 2026

Screenshot of chrome-authenticator.com taken by the zone census on 2026-09-10

Same data as JSON: /api/zone/domain/chrome-authenticator.com. This page is not indexed by search engines and does not link to the site it describes.