tilio.click
Appeared in the .click zone on Tuesday, September 15, 2026; by the end of that day the census found empty page. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Page is a self-branded Spanish-language SaaS login ('Tilio · Control simple para negocios reales' — inventory/sales management) with its own logo, sign-up and invitation flows, hosted on Vercel; nothing mimics Twilio's branding, product language or portal, so the 'tilio≈twilio' string similarity alone is not evidence of impersonation.
Domain 'tilio.click' is a typosquat of Twilio (brand-typo similarity score 28). The page displays a login form titled 'Iniciar sesión' (Sign in) in Spanish, impersonating Twilio's branding with the characteristic teal/green logo and tagline 'Tu negocio, más simple' (Your business, simpler), asking for email and password credentials. The form posts to itself with no offsite links—the sealed-room phishing pattern—designed to capture Twilio customer credentials.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Tuesday, September 15, 2026

Same data as JSON: /api/zone/domain/tilio.click. This page is not indexed by search engines and does not link to the site it describes.