votei-tme.click
Appeared in the .click zone on Wednesday, October 7, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The name 'votei-tme' combines 'vote' with 'tme' (Telegram's t.me), matching the well-known fake-voting lure used to steal Telegram accounts. It sits on a throwaway .click domain behind Cloudflare, and its redirect of our crawler to google.com fits phishing-kit cloaking rather than any legitimate use; the lure page itself was not observed.
The domain votei-tme.click is a brand-typosquat (containing 'vote' and 'tme', likely targeting voters or election-related searches) registered with Cloudflare nameservers and configured to redirect to Google's legitimate homepage. This is a classic redirect-squat: the attacker controls the malicious domain but immediately bounces visitors to a real site to evade detection, while the domain itself sits ready for future abuse (credential harvesting, malware injection, or SEO manipulation). The .cl
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Wednesday, October 7, 2026

Same data as JSON: /api/zone/domain/votei-tme.click. This page is not indexed by search engines and does not link to the site it describes.