Criticalscore 60 · flagged Saturday, September 19, 2026

stpastry.shop

Appeared in the .shop zone on Saturday, September 19, 2026; by the end of that day the census found active website about food & restaurants. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

page impersonates a brand
matched: PayPal
+22
brand in page title, not in the name
matched: nationwide
+20
form on a brand-styled page
matched: has_form
+18
Registrar
Nameserver provider
Nameservers
ns1.dyna-ns.net, ns2.dyna-ns.net
First-day state
active website
HTTP status
200
Page title
Gourmet Pecan Cakes, Fruitcakes & Handcrafted Treats | Collin Street Bakery
Has a form
yes
Brand echoed

Model opinions

Second opinionlooks like phishingtarget: Collin Street Bakeryconfidence 78%· claude-opus-5

Domain stpastry.shop hosts a full clone of Collin Street Bakery, using its logo, tagline and product catalogue at implausible 65% discounts with an account/cart checkout — a brand-impersonating fake storefront designed to harvest card payments and personal data; the unrelated domain name and no offsite links to the real bakery confirm it is not the brand's own site.

First passlooks like phishingtarget: Collin Street Bakeryconfidence 92%· claude-haiku-4-5

The page impersonates Collin Street Bakery (a real Texas bakery established 1896) by using its distinctive logo, tagline 'Built in Corsicana, Texas since 1876', and branding throughout. The domain stpastry.shop is not owned by Collin Street Bakery. The presence of a password form posting to itself with hidden action fields, combined with no offsite links and PayPal payment language, creates a sealed-room credential-capture setup typical of phishing—visitors will enter payment and account details

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Saturday, September 19, 2026

Screenshot of stpastry.shop taken by the zone census on 2026-09-19

Same data as JSON: /api/zone/domain/stpastry.shop. This page is not indexed by search engines and does not link to the site it describes.