Criticalscore 76 · flagged Tuesday, September 22, 2026

proxytelegram.bond

Appeared in the .bond zone on Tuesday, September 22, 2026; by the end of that day the census found active website about hosting & domains. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: telegram
+30
TLD with a high abuse rate
matched: bond
+8
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: Porkbun LLC
+8
brand name at a watch-list registrar
matched: Porkbun LLC
+6
form on a brand-styled page
matched: has_form
+18
Registrar
Porkbun LLC
Nameserver provider
Nameservers
brenda.ns.cloudflare.com, cesar.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
Прокси для телеграм — рабочие серверы бесплатно, 22 сентября 2026
Has a form
yes
Brand echoed
telegram

Model opinions

Second opinionsuspiciousconfidence 60%· claude-opus-5

Russian-language MTProto proxy list using Telegram's brand in the domain name; there is no Telegram login or credential capture (the only form is a GET text/link field), but it is part of a sibling network (mtprotoproxy.bond, mtprotohub.bond, proxytg.cfd, mtproto.fyi) pushing 'Prime VPN' affiliate links and third-party proxies that can intercept traffic — brand-leveraged monetisation that falls short of demonstrated phishing.

First passlooks like abuseconfidence 85%· claude-haiku-4-5

The domain proxytelegram.bond is a typosquat/brand-squat hosting a proxy-server directory that leverages Telegram's brand name to distribute circumvention infrastructure. While it does not impersonate Telegram's login or account portal to steal credentials, it exploits the Telegram brand to attract users seeking censorship-bypass proxies, likely for use in restricted regions. The operator contact via Telegram (t.me) and the sealed-room form design (posting to self with no legitimate offsite vali

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Tuesday, September 22, 2026

Screenshot of proxytelegram.bond taken by the zone census on 2026-09-22

Same data as JSON: /api/zone/domain/proxytelegram.bond. This page is not indexed by search engines and does not link to the site it describes.