Highscore 55 · flagged Monday, October 5, 2026

publique-service-ch.top

Appeared in the .top zone on Monday, October 5, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

lure words (login, verify, secure…)
matched: service
+6
TLD with a high abuse rate
matched: top
+8
free DNS provider
matched: dnsowl.com
+8
brand in page title, not in the name
matched: google
+20
form on a brand-styled page
matched: has_form
+18
Registrar
NameSilo,LLC
Nameserver provider
Nameservers
ns1.dnsowl.com, ns2.dnsowl.com, ns3.dnsowl.com
First-day state
redirects elsewhere
HTTP status
200
Page title
Google
Has a form
yes
Brand echoed
—

Model opinions

Second opinionsuspicioustarget: Swiss public administration (ch.ch)confidence 60%· claude-opus-5-5

The name 'publique-service-ch' mimics a Swiss government 'service public' portal on a cheap .top domain with NameSilo/dnsowl DNS. It currently redirects to google.com, a common cloaking shape for phishing kits that hide content from scanners, but no impersonating page is served yet. The Google branding and form belong to the real destination and are not evidence against this domain.

First passlooks like phishingtarget: Googleconfidence 95%· claude-haiku-4-5

The domain name 'publique-service-ch.top' impersonates a Swiss public service to deceive visitors into believing they are accessing an official site, then redirects to Google's homepage to capture credentials via the search/signin form. The use of free DNS (dnsowl.com), a typosquat-style name with 'service' and Swiss country signifiers, combined with the redirect to a legitimate Google page containing a login form, is a classic phishing setup designed to harvest credentials by exploiting trust i

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Monday, October 5, 2026

Screenshot of publique-service-ch.top taken by the zone census on 2026-10-05

Same data as JSON: /api/zone/domain/publique-service-ch.top. This page is not indexed by search engines and does not link to the site it describes.