Highscore 55 · flagged Saturday, October 10, 2026

update-ato-services-info-au-login.cfd

Appeared in the .cfd zone on Saturday, October 10, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

lure words (login, verify, secure…)
matched: login,service,services,update
+18
many hyphens
matched: 5
+6
very long name
matched: 33
+4
TLD with a high abuse rate
matched: cfd
+8
brand in page title, not in the name
matched: google
+20
form on a brand-styled page
matched: has_form
+18
Registrar
OwnRegistrar, Inc.
Nameserver provider
Nameservers
clay.ns.cloudflare.com, maleah.ns.cloudflare.com
First-day state
redirects elsewhere
HTTP status
200
Page title
Google
Has a form
yes
Brand echoed
—

Model opinions

Second opinionlooks like phishingtarget: Australian Taxation Office (ATO)confidence 80%· claude-opus-5-5

The name strings ATO tax-portal lure words ('update-ato-services-info-au-login') on a throwaway .cfd TLD behind Cloudflare, and the bounce to google.com is a typical cloaking redirect for non-targeted visitors. The Google page is only the redirect destination and not the impersonated brand.

First passlooks like phishingtarget: Australian Taxation Office (ATO)confidence 92%· claude-haiku-4-5

Domain name impersonates ATO ('update-ato-services-info-au-login') with lure words (login, update, services, au) and a suspicious .cfd TLD, designed to deceive visitors seeking ATO services. The redirect to google.com is a decoy masking the phishing intent; the domain's infrastructure and naming convention establish that it was set up to capture credential-seekers before redirecting them away to obscure the attack.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Saturday, October 10, 2026

Screenshot of update-ato-services-info-au-login.cfd taken by the zone census on 2026-10-10

Same data as JSON: /api/zone/domain/update-ato-services-info-au-login.cfd. This page is not indexed by search engines and does not link to the site it describes.