helsna-service.online
Appeared in the .online zone on Friday, August 28, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The domain serves no content of its own and simply bounces visitors to www.google.com — a common holding/cloaking state for a newly registered name behind Cloudflare NS; all Google branding in the evidence belongs to the redirect destination, not this host. The name pattern ('<brandish-word>-service.online', plausibly a squat on the Swiss insurer Helsana) plus a Dynadot registration and a placeholder redirect is the typical dormant setup for a later credential-harvesting page, but there is no de
The domain helsna-service.online is a typosquat with 'service' (lure-word) that redirects to www.google.com, creating a deceptive path to Google's login. The domain name does not belong to Google, yet it transparently serves Google's page to harvest credentials through the redirect chain—a classic phishing infrastructure setup.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Friday, August 28, 2026

Same data as JSON: /api/zone/domain/helsna-service.online. This page is not indexed by search engines and does not link to the site it describes.