cloudflarewallet.click
Appeared in the .click zone on Friday, September 4, 2026; by the end of that day the census found server error. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
cloudflarewallet.click combines the Cloudflare brand with a crypto 'wallet' lure on a cheap .click TLD, but serves only a Cloudflare 521 error page with no content of its own; a brand-squat with no legitimate purpose, staged behind Cloudflare NS and awaiting content (likely a wallet-credential phish once live).
The domain cloudflarewallet.click combines 'cloudflare' and 'wallet' (a financial/credential lure word) with a .click TLD frequently used in phishing. The domain is registered with Cloudflare's own nameservers and uses a retail registrar, which are hallmarks of phishing infrastructure setup. However, the page currently shows only a standard Cloudflare 521 error (host down), so no active phishing page is presently visible—but the domain name, registration pattern, and nameserver choice strongly s
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Friday, September 4, 2026

Same data as JSON: /api/zone/domain/cloudflarewallet.click. This page is not indexed by search engines and does not link to the site it describes.