Highscore 46 · flagged Sunday, September 13, 2026

dom-gin.quest

Appeared in the .quest zone on Sunday, September 13, 2026; by the end of that day the census found active website about education. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: quest
+8
brand in page title, not in the name
matched: steam
+20
form on a brand-styled page
matched: has_form
+18
Registrar
Nameserver provider
Nameservers
curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com
First-day state
active website
HTTP status
200
Page title
Активация и настройка VR-гарнитур Quest и Pico под ключ | dom-gin.quest
Has a form
yes
Brand echoed

Model opinions

Second opinionsuspiciousconfidence 58%· claude-opus-5

Russian-language 'grey market' service page offering remote activation/setup of Meta Quest and Pico VR headsets (account creation, developer mode, Global ROM, utility installs) via AnyDesk/RustDesk remote control with only Telegram/WhatsApp contacts and no legal entity — the 'steam' brand flag is a false hit and there is no credential-capture form, but the remote-access-plus-messenger-operator shape and unverifiable anonymous operator make it plausibly a remote-access/account scam front rather t

First passlooks like phishingtarget: Meta (Quest VR headsets)confidence 92%· claude-haiku-4-5

The domain impersonates Meta's Quest brand by offering VR headset 'activation and setup' services under a deceptive domain name (dom-gin.quest), with a form collecting user company information posted to self, and operator contact via Telegram/WhatsApp—a classic phishing setup targeting business customers or resellers who may have legitimate need for Quest device management but are being redirected to a fraudulent service page designed to harvest credentials or payment details.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, September 13, 2026

Screenshot of dom-gin.quest taken by the zone census on 2026-09-13

Same data as JSON: /api/zone/domain/dom-gin.quest. This page is not indexed by search engines and does not link to the site it describes.