downvip1.lol
Appeared in the .lol zone on Thursday, August 27, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The page shown is not hosted content but an off-site redirect to the genuine https://dns.google/ (real Google Public DNS), so the Google branding and form are Google's own and not impersonation; however the name is part of a numbered campaign shape (downvip0-9.lol) on a cheap .lol TLD behind Cloudflare, parked temporarily on a legitimate third-party site, which is a common staging pattern worth watching.
The domain downvip1.lol impersonates Google Public DNS by displaying Google's logo, branding, and page title ('Google Public DNS') to deceive visitors into believing they are on Google's legitimate service. The presence of a form combined with the .lol TLD (a known abuse vector), the domain name structure (downvip1), and the redirect-offsite behavior indicate this is a credential-harvesting phishing page masquerading as Google's DNS tool.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Thursday, August 27, 2026

Same data as JSON: /api/zone/domain/downvip1.lol. This page is not indexed by search engines and does not link to the site it describes.