docusignni.icu
Appeared in the .icu zone on Wednesday, September 9, 2026; by the end of that day the census found empty page. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Newly registered .icu domain that embeds the DocuSign brand ('docusignni') with no legitimate connection to the company; the origin serves nothing (Cloudflare 520 error page), so there is no content yet to phish with, but a DocuSign-named domain on a cheap TLD behind Cloudflare with a retail registrar has no plausible non-deceptive purpose and matches known DocuSign e-signature phishing infrastructure.
The domain displays a standard Cloudflare error page (520 error) indicating a connection failure between Cloudflare and the origin server. This is a hosting/infrastructure failure, not a phishing page. The page title 'Redirecting...' and error message are Cloudflare's own placeholder content, not an attempt to impersonate DocuSign or capture credentials.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Wednesday, September 9, 2026

Same data as JSON: /api/zone/domain/docusignni.icu. This page is not indexed by search engines and does not link to the site it describes.