portal-minha-encomenda.click
Appeared in the .click zone on Friday, September 11, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name 'portal-minha-encomenda' ('my parcel portal' in Portuguese) is a textbook parcel-delivery lure on a cheap .click TLD, but the host serves no content of its own — it simply redirects to www.google.com, a common cloaking/holding state while an SMS parcel campaign is staged. All brand signals in the evidence (Google title, sign-in link, search form) belong to the redirect destination and are not impersonation by this domain, so there is no decisive deception yet.
The domain 'portal-minha-encomenda.click' uses a lure name ('portal' + Portuguese parcel language 'encomenda') combined with the suspicious .click TLD to mimic a parcel/package tracking portal, then redirects to Google's legitimate homepage. This is a typosquat/redirect scheme: the domain itself is the abuse vector, using deceptive naming to trick users into visiting it expecting a parcel portal, then profiting from or logging the redirect. The redirect to Google is incidental; the abuse is the
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Friday, September 11, 2026

Same data as JSON: /api/zone/domain/portal-minha-encomenda.click. This page is not indexed by search engines and does not link to the site it describes.