Highscore 46 · flagged Thursday, October 1, 2026

mofuzinaly.bond

Appeared in the .bond zone on Thursday, October 1, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: bond
+8
brand in page title, not in the name
matched: google
+20
form on a brand-styled page
matched: has_form
+18
Registrar
NameSilo, LLC
Nameserver provider
Nameservers
benedict.ns.cloudflare.com, carlane.ns.cloudflare.com
First-day state
redirects elsewhere
HTTP status
200
Page title
Google
Has a form
yes
Brand echoed
—

Model opinions

Second opinionsuspiciousconfidence 55%· claude-opus-5-5

The domain serves no content of its own and simply redirects to the real www.google.com, so the Google branding and form belong to Google and are not impersonation. Still, a random pronounceable name on the high-abuse .bond TLD, registered via NameSilo behind Cloudflare and bouncing visitors to google.com, matches a common cloaking or staging pattern for throwaway abuse domains, though nothing malicious is shown yet.

First passlooks like abusetarget: Googleconfidence 92%· claude-haiku-4-5

The domain mofuzinaly.bond is a non-descriptive typosquat that redirects to Google's legitimate homepage. The domain name itself has no legitimate purpose—'mofuzinaly' is gibberish with no connection to Google's services. This is a classic brand-squat redirect setup: the attacker registered an obscure .bond domain, pointed it at Google via Cloudflare nameservers, and now any traffic to the typosquat arrives at Google's real site. The intent is deceptive registration for potential phishing infras

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Thursday, October 1, 2026

Screenshot of mofuzinaly.bond taken by the zone census on 2026-10-01

Same data as JSON: /api/zone/domain/mofuzinaly.bond. This page is not indexed by search engines and does not link to the site it describes.