Highscore 55 · flagged Tuesday, September 1, 2026

josedisableionos001.online

Appeared in the .online zone on Tuesday, September 1, 2026; by the end of that day the census found registrar placeholder. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: ionos
+14
brand plus digits
matched: josedisableionos001
+8
brand name at a retail registrar
matched: IONOS SE
+8
form on a brand-styled page
matched: has_form
+18
identical page on many newborns
matched: 1139 identical pages
+10
Registrar
IONOS SE
Nameserver provider
Nameservers
ns1065.ui-dns.org, ns1074.ui-dns.com, ns1114.ui-dns.de, ns1115.ui-dns.biz
First-day state
registrar placeholder
HTTP status
200
Page title
Has a form
yes
Brand echoed
ionos

Model opinions

Second opinionlooks benignconfidence 90%· claude-opus-5

The page is IONOS's own genuine registrar placeholder ('Diese Domain ist bereits registriert'), served from IONOS nameservers under IONOS SE, with the only form being IONOS's domain-search box and links to ionos.de — one of 1139 identical registrar pages, not an impersonation attempt; the 'ionos' string in the odd name appears to be an internal/test label rather than a deceptive squat.

First passlooks like phishingtarget: IONOSconfidence 95%· claude-haiku-4-5

The page impersonates IONOS's domain management portal with the IONOS logo, German-language interface claiming the domain is 'already registered at IONOS', and a login button ('Domain verwalten') designed to capture credentials. The sealed-room form architecture (posting to self with hidden SYNT parameters) combined with 1,139 identical clustered domains and the typosquat name 'josedisableionos001.online' confirms this is a credential-harvesting phishing campaign, not a legitimate IONOS page.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Tuesday, September 1, 2026

Screenshot of josedisableionos001.online taken by the zone census on 2026-09-01

Same data as JSON: /api/zone/domain/josedisableionos001.online. This page is not indexed by search engines and does not link to the site it describes.