teleg-votel.click
Appeared in the .click zone on Sunday, September 20, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name 'teleg-votel.click' mangles the Telegram brand plus 'vote', the exact shape of the long-running Telegram 'vote for my child/contest' login-code phishing campaign, and it serves no page of its own — it bounces visitors offsite to google.com, a classic cloak/holding state on a cheap .click name behind Cloudflare NS. The Google branding shown belongs to the redirect destination and is not impersonation by this domain, so the evidence points to a staged Telegram phish but is not yet decisiv
The domain teleg-votel.click is a typosquat (blending 'telegram' and 'hotel' with 'votel' phonetically) that redirects to Google's legitimate homepage. This is a classic redirect-squat abuse pattern: the deceptive domain name has no legitimate purpose, and redirecting to Google serves no user value—it exists only to capture clicks or traffic from users typing a misspelled domain, then profit from the redirect. The name itself is the abuse; the redirect destination being Google's real site does n
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Sunday, September 20, 2026

Same data as JSON: /api/zone/domain/teleg-votel.click. This page is not indexed by search engines and does not link to the site it describes.