Highscore 55 · flagged Thursday, October 8, 2026

usps-us.blog

Appeared in the .blog zone on Thursday, October 8, 2026; by the end of that day the census found redirects elsewhere. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: usps
+30
brand name at a retail registrar
matched: Porkbun, LLC
+8
brand name at a watch-list registrar
matched: Porkbun, LLC
+6
brand in page title, not in the name
matched: google
+20
form on a brand-styled page
matched: has_form
+18
brand name redirects elsewhere
matched: google.com
+8
Registrar
Porkbun, LLC
Nameserver provider
Nameservers
curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com
First-day state
redirects elsewhere
HTTP status
200
Page title
Google
Has a form
yes
Brand echoed
usps

Model opinions

Second opinionlooks like abusetarget: USPSconfidence 80%· claude-opus-5-5

The name 'usps-us' brand-squats USPS, and the domain is newly registered at a retail registrar and serves no content of its own. It redirects to google.com, a common cloaking pattern for USPS parcel-smishing infrastructure that hides the phishing page from non-target visitors. The Google page and form are the redirect destination's, not impersonation by this domain.

First passlooks like abuseconfidence 92%· claude-haiku-4-5

The domain usps-us.blog is a USPS typosquat that redirects to Google's legitimate homepage. The redirect itself is benign, but the domain name—combining a US government brand (USPS) with a generic TLD—is a classic brand-squat with no legitimate purpose. The redirect to Google.com appears to be a redirect-farming or SEO manipulation tactic rather than active phishing, but the registration pattern (Porkbun registrar, off-brand nameservers, typosquat name) and the combination of two unrelated brand

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Thursday, October 8, 2026

Screenshot of usps-us.blog taken by the zone census on 2026-10-08

Same data as JSON: /api/zone/domain/usps-us.blog. This page is not indexed by search engines and does not link to the site it describes.