Highscore 55 · flagged Monday, August 31, 2026

tech-postback.fun

Appeared in the .fun zone on Monday, August 31, 2026; by the end of that day the census found boilerplate page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

one-letter brand typo
matched: postback≈postbank
+28
TLD with a high abuse rate
matched: fun
+8
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+8
brand name at a watch-list registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+6
Registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED
Nameserver provider
Nameservers
clarissa.ns.cloudflare.com, lochlan.ns.cloudflare.com
First-day state
boilerplate page
HTTP status
200
Page title
Has a form
no
Brand echoed
postbank

Model opinions

Second opinionsuspiciousconfidence 50%· claude-opus-5

"postback" is a standard ad-tech server-to-server tracking term, so the Postbank typo match is almost certainly a false positive; the site serves only a bare "Error 404" boilerplate with no form or links. Blank tracker-style hostnames on .fun behind Cloudflare via a bulk retail registrar are commonly used as redirect/postback infrastructure in affiliate or malvertising chains, but there is no content here to prove abuse.

First passsuspiciousconfidence 65%· claude-haiku-4-5

The domain name contains 'postback' which shows phonetic similarity to 'Postbank' (a real financial institution), combined with a .fun TLD and registration through a bulk registrar flagged for watch-list activity. However, the current page is merely a 404 error with no deceptive content, login form, or impersonation attempt visible. The suspicion is based on naming patterns and infrastructure rather than active abuse on the current page.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Monday, August 31, 2026

Screenshot of tech-postback.fun taken by the zone census on 2026-08-31

Same data as JSON: /api/zone/domain/tech-postback.fun. This page is not indexed by search engines and does not link to the site it describes.