Criticalscore 85 · flagged Monday, September 21, 2026

paypalreq.space

Appeared in the .space zone on Monday, September 21, 2026; by the end of that day the census found active website. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: paypal
+30
page impersonates a brand
matched: PayPal
+22
brand name and brand-styled page
matched: paypal
+15
form on a brand-styled page
matched: has_form
+18
Registrar
Nameserver provider
Nameservers
ns1.vercel-dns.com, ns2.vercel-dns.com
First-day state
active website
HTTP status
200
Page title
PayPal | Security Update
Has a form
yes
Brand echoed
paypal

Model opinions

Second opinionlooks like phishingtarget: PayPalconfidence 97%· claude-opus-5

Domain 'paypalreq.space' contains the PayPal brand and serves a page titled 'PayPal | Security Update' with a credential re-entry form and urgency language ('Action Required... re-entering your credentials'), hosted on Vercel — a classic PayPal credential-harvesting page.

First passlooks like phishingtarget: PayPalconfidence 95%· claude-haiku-4-5

Domain name contains 'paypal', page title impersonates PayPal with 'PayPal | Security Update', and the page contains a form requesting credential re-entry under false pretense of a 'security update' and 'session anomaly'—a classic phishing technique to harvest login credentials.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

Same data as JSON: /api/zone/domain/paypalreq.space. This page is not indexed by search engines and does not link to the site it describes.