Highscore 55 · flagged Sunday, October 4, 2026

xn--icld-ix5a8f.com

Appeared in the .com zone on Sunday, October 4, 2026; by the end of that day the census found redirect not followed. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

punycode name
matched: iclọụd scripts=LATIN
+18
brand in the name
matched: icloud
+10
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: Sav.com, LLC
+8
brand name at a watch-list registrar
matched: Sav.com, LLC
+6
brand name redirects elsewhere
matched: google.com
+8
Registrar
Sav.com, LLC
Nameserver provider
Nameservers
barbara.ns.cloudflare.com, koa.ns.cloudflare.com
First-day state
redirect not followed
HTTP status
303
Page title
—
Has a form
no
Brand echoed
icloud

Model opinions

Second opinionlooks like abusetarget: Apple (iCloud)confidence 85%· claude-opus-5-5

The punycode name decodes to 'iclọụd', a homoglyph of Apple's iCloud built from dotted Latin lookalike letters. It was registered through retail registrar Sav.com behind Cloudflare, not by Apple. It serves no content of its own and only 303-redirects to Google Maps, a typical holding or cloaking pattern for a brand homograph whose only plausible purpose is deception.

First passsuspiciousconfidence 72%· claude-haiku-4-5

The punycode domain mimics 'iCloud' (Apple brand) but redirects to Google's consent page with legitimate Google Maps parameters. While the redirect itself is to Google's real domain, the combination of a brand-typosquat name (iclọụd), Cloudflare nameservers, and a retail registrar suggests potential infrastructure for deception, though the current redirect appears benign rather than actively phishing.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, October 4, 2026

Screenshot of xn--icld-ix5a8f.com taken by the zone census on 2026-10-04

Same data as JSON: /api/zone/domain/xn--icld-ix5a8f.com. This page is not indexed by search engines and does not link to the site it describes.