Criticalscore 68 · flagged Monday, September 28, 2026

dropdial.fun

Appeared in the .fun zone on Monday, September 28, 2026; by the end of that day the census found active website about e-commerce & retail. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: fun
+8
page impersonates a brand
matched: MetaMask
+22
brand in page title, not in the name
matched: robinhood
+20
form on a brand-styled page
matched: has_form
+18
Registrar
—
Nameserver provider
Nameservers
launch1.spaceship.net, launch2.spaceship.net
First-day state
active website
HTTP status
200
Page title
Dropdial · The coin clock on Robinhood Chain
Has a form
yes
Brand echoed
—

Model opinions

Second opinionlooks benignconfidence 60%· claude-opus-5-5

Dropdial is its own brand: a Dutch-auction coin-launch site that names Robinhood Chain as the network it runs on and offers standard 'Open in MetaMask/Trust/Coinbase Wallet' deeplinks, rather than posing as Robinhood or MetaMask. The page openly states it is a preview with no deployed contract and that bidding is disabled, and nothing collects credentials or seed phrases, though a new .fun memecoin launchpad deserves re-checking once it goes live.

First passsuspiciousconfidence 72%· claude-haiku-4-5

The page has a wallet-connection form ('Connect wallet', 'Open in MetaMask') and references MetaMask impersonation signals (22 weight), but the actual page content describes a Dutch-auction NFT/token launch mechanism on 'Robinhood Chain' with its own Dropdial branding, not a fake MetaMask or Robinhood login. The brand-in-title mismatch (Robinhood Chain mentioned but not in domain name) and form-on-brand-page signals suggest DeFi phishing infrastructure, but no credentials or payment data capture

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

Same data as JSON: /api/zone/domain/dropdial.fun. This page is not indexed by search engines and does not link to the site it describes.