verify-mobile-esl.cfd
Appeared in the .cfd zone on Tuesday, September 8, 2026; by the end of that day the census found boilerplate page. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The live page is only the default CyberPanel hosting control-panel login (server boilerplate on nginx/Ubuntu), so no brand is being impersonated yet; however the name pattern 'verify-mobile-<brand>' on a cheap .cfd via Spaceship is classic staging for an SMS/mobile-banking 'verify your account' phish (ESL Federal Credit Union / T-Mobile style lure), so it warrants monitoring rather than a phishing call today.
The domain name contains 'verify-mobile' which triggers T-Mobile typosquat signals, and the page hosts a login form posting to itself with no offsite links—a sealed-room phishing shape. However, the page displays legitimate CyberPanel branding and infrastructure (OpenLiteSpeed/LiteSpeed, CyberPanel logo, multilingual control panel UI), suggesting this may be a compromised or misconfigured hosting panel rather than deliberate T-Mobile impersonation. The password form collecting credentials is the
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Tuesday, September 8, 2026

Same data as JSON: /api/zone/domain/verify-mobile-esl.cfd. This page is not indexed by search engines and does not link to the site it describes.