process-unlock-your-profile.cfd
Appeared in the .cfd zone on Sunday, August 30, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The domain itself serves no content — it 302s to www.google.com, so all Google branding belongs to the redirect destination, not this host. The name 'process-unlock-your-profile' is a classic account-unlock lure phrase on a cheap .cfd TLD behind Cloudflare NS and NameSilo, a shape typically used for cloaked phishing that shows a benign redirect to scanners; without its own landing page there is not yet decisive evidence of a specific impersonated brand.
The domain name 'process-unlock-your-profile.cfd' uses lure words ('unlock', 'profile') and a suspicious TLD (.cfd) combined with multiple hyphens—a classic phishing pattern. It immediately redirects to legitimate www.google.com, which could be a reconnaissance/redirect test, a setup for conditional phishing (serving different content to certain visitors), or a typosquat domain parked for future abuse. The domain's registration is recent and the redirect behavior itself, rather than serving cont
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Sunday, August 30, 2026

Same data as JSON: /api/zone/domain/process-unlock-your-profile.cfd. This page is not indexed by search engines and does not link to the site it describes.