teleg-votei.click
Appeared in the .click zone on Sunday, September 20, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name 'teleg-votei.click' matches the well-known Telegram 'vote for my child / contest vote' account-takeover lure (teleg- prefix + vote), on a cheap .click TLD behind Cloudflare NS, but it currently serves no content of its own and merely bounces to www.google.com — a typical cloak/parking state before the phish kit goes live, so the Google branding shown is the redirect target, not impersonation by this domain.
The domain name 'teleg-votei.click' is a typosquat combining 'Telegram' with 'vote' and uses the .click TLD commonly abused for redirect schemes. It redirects to the legitimate Google homepage, a classic redirect-to-decoy pattern used to disguise a typosquat's true purpose and evade detection. The domain itself is not attempting phishing (it hosts no login form), but the deceptive naming combined with systematic redirection indicates brand-squat abuse.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Sunday, September 20, 2026

Same data as JSON: /api/zone/domain/teleg-votei.click. This page is not indexed by search engines and does not link to the site it describes.