Criticalscore 62 · flagged Saturday, October 10, 2026

fedexswiss.online

Appeared in the .online zone on Saturday, October 10, 2026; by the end of that day the census found active website about corporate services. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: fedex
+30
brand name at a retail registrar
matched: HOSTINGER operations, UAB
+8
brand name at a watch-list registrar
matched: HOSTINGER operations, UAB
+6
form on a brand-styled page
matched: has_form
+18
Registrar
HOSTINGER operations, UAB
Nameserver provider
Nameservers
ns1.dns-parking.com, ns2.dns-parking.com
First-day state
active website
HTTP status
200
Page title
Delivering Across Borders, Tracked to Your Door - FEDEXSWISS
Has a form
yes
Brand echoed
fedex

Model opinions

Second opinionlooks like phishingtarget: FedExconfidence 86%· claude-opus-5-5

The site 'FEDEXSWISS' shows a FedEx-style logo and offers shipment tracking and quote forms, but it sits on a Hostinger parking-NS .online domain that FedEx does not own. Its only operator contact is a WhatsApp chat widget, which fits the fake-courier pattern used to collect 'customs fees' and personal data.

First passlooks like phishingtarget: FedExconfidence 95%· claude-haiku-4-5

Domain impersonates FedEx with a modified name (fedexswiss.online) and FedEx branding/logo on the page. The site hosts a form posting to itself with no legitimate business purpose, WhatsApp operator contact, and mimics FedEx's tracking/logistics services to deceive visitors into providing credentials or personal data. The 'sealed-room' form architecture (self-posting, no offsite links except operator contact) is a classic phishing pattern.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Saturday, October 10, 2026

Screenshot of fedexswiss.online taken by the zone census on 2026-10-10

Same data as JSON: /api/zone/domain/fedexswiss.online. This page is not indexed by search engines and does not link to the site it describes.