forsheincustomer.icu
Appeared in the .icu zone on Saturday, August 29, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Name 'forsheincustomer' is a Shein brand-squat combined with a fake customer-support lure on a cheap .icu TLD, yet it serves no content of its own — it merely redirects to www.google.com, a classic cloaking/holding pattern while the fake support/phish page is staged. The Google branding shown is the redirect destination, not this domain's content.
The domain 'forsheincustomer.icu' is a typosquat or brand-squat with 'customer' lure-word and .icu TLD (high-abuse indicator). It redirects to www.google.com, which is a redirect abuse tactic; the domain itself does not host phishing content, but the registration pattern (brand-adjacent name + offsite redirect to a legitimate site) is consistent with redirect abuse for traffic capture or SEO manipulation rather than credential phishing.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Saturday, August 29, 2026

Same data as JSON: /api/zone/domain/forsheincustomer.icu. This page is not indexed by search engines and does not link to the site it describes.