Highscore 54 · flagged Saturday, September 5, 2026

linkedon.app

Appeared in the .app zone on Saturday, September 5, 2026; by the end of that day the census found blocked the probe. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

one-letter brand typo
matched: linkedon≈linkedin
+28
brand name at a retail registrar
matched: GoDaddy.com, LLC
+8
form on a brand-styled page
matched: has_form
+18
Registrar
GoDaddy.com, LLC
Nameserver provider
Nameservers
ns39.domaincontrol.com, ns40.domaincontrol.com
First-day state
blocked the probe
HTTP status
200
Page title
linkedon.app
Has a form
yes
Brand echoed
linkedin

Model opinions

First passsuspicioustarget: LinkedInconfidence 72%· claude-haiku-4-5

The domain linkedon.app is a typosquat of LinkedIn with a form present, but the page shows only a generic 'Launching Soon' placeholder with a newsletter signup, not an impersonation attempt to capture credentials. The form collects name and email for a mailing list rather than pretending to be LinkedIn's login or account portal, which weakens the phishing signal despite the clear typo and GoDaddy registration pattern.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

Same data as JSON: /api/zone/domain/linkedon.app. This page is not indexed by search engines and does not link to the site it describes.