Criticalscore 60 · flagged Sunday, September 20, 2026

dpotmozotoxico.lat

Appeared in the .lat zone on Sunday, September 20, 2026; by the end of that day the census found active website about saas & tech. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

page impersonates a brand
matched: DHL
+22
brand in page title, not in the name
matched: fedex
+20
form on a brand-styled page
matched: has_form
+18
Registrar
Nameserver provider
Nameservers
brynne.ns.cloudflare.com, neil.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
Rastreo MX - Controla todos tus paquetes y envíos en una sola App
Has a form
yes
Brand echoed

Model opinions

Second opinionsuspiciousconfidence 55%· claude-opus-5

Polished Spanish-language "Rastreo MX" parcel-tracking aggregator landing page pushing a Google Play app, hosted on a random, meaningless .lat domain (dpotmozotoxico) behind Cloudflare — the carrier names (DHL, FedEx, Estafeta, Correos de México) are listed as supported services rather than impersonated, and the only form takes a tracking number, not credentials; the name/content mismatch and disposable TLD suggest a throwaway app-install/lead funnel but there is no decisive deception on the pag

First passlooks like phishingtarget: DHL, FedExconfidence 85%· claude-haiku-4-5

The page impersonates a legitimate package-tracking aggregator ('Rastreo MX') but contains a form posting to itself with tracking number fields, a classic phishing sealed-room pattern. The domain name itself is meaningless ('dpotmozotoxico'), the page prominently features DHL and FedEx branding and mentions them as supported carriers to establish false trust, and the form has no legitimate backend—it is designed to capture tracking numbers and personal data entered by users who believe they are

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, September 20, 2026

Screenshot of dpotmozotoxico.lat taken by the zone census on 2026-09-20

Same data as JSON: /api/zone/domain/dpotmozotoxico.lat. This page is not indexed by search engines and does not link to the site it describes.