Highscore 55 · flagged Monday, September 28, 2026

mobile-pay-dk.site

Appeared in the .site zone on Monday, September 28, 2026; by the end of that day the census found not probed yet. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

one-letter brand typo
matched: mobile≈tmobile
+28
lure words (login, verify, secure…)
matched: pay
+26
brand name behind Cloudflare
matched: cloudflare.com
+6
Registrar
—
Nameserver provider
Nameservers
asa.ns.cloudflare.com, rory.ns.cloudflare.com
First-day state
not probed yet
HTTP status
—
Page title
—
Has a form
no
Brand echoed
tmobile

Model opinions

Second opinionlooks like abusetarget: MobilePay (Vipps MobilePay)confidence 60%· claude-opus-5-5

The name 'mobile-pay-dk' matches MobilePay, Denmark's dominant mobile-payment brand, on a cheap .site TLD. MobilePay does not own it, so this looks like a brand-squat. The scorer's T-Mobile match is a misread. There is no page content, form or infrastructure data yet, so it cannot be called phishing.

First passsuspicioustarget: tmobileconfidence 53%· typesafe/jev-latest

typesafe first pass (gate 0.4): p=suspicious:0.61 abuse:0.36 unreachable:0.02 | impersonates=0.58 credential=0.18 parked=0.67 evidence=1.0 | target=tmobile:0.91

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

Same data as JSON: /api/zone/domain/mobile-pay-dk.site. This page is not indexed by search engines and does not link to the site it describes.