Highscore 55 · flagged Tuesday, September 1, 2026

yl-cloud-web-ssecurity.top

Appeared in the .top zone on Tuesday, September 1, 2026; by the end of that day the census found boilerplate page. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

one-letter brand typo
matched: cloud≈icloud
+28
lure words (login, verify, secure…)
matched: security
+26
many hyphens
matched: 3
+6
TLD with a high abuse rate
matched: top
+8
brand name at a retail registrar
matched: Porkbun LLC
+8
brand name at a watch-list registrar
matched: Porkbun LLC
+6
identical page on many newborns
matched: 2321 identical pages
+10
Registrar
Porkbun LLC
Nameserver provider
Nameservers
curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com
First-day state
boilerplate page
HTTP status
403
Page title
403 Forbidden
Has a form
no
Brand echoed
icloud

Model opinions

Second opinionsuspiciousconfidence 50%· claude-opus-5

The only content is Porkbun's own 'This domain is expired' registrar placeholder (403, no forms other than Porkbun's domain search), so there is nothing deceptive being served today; however the name pattern (yl-cloud-web-ssecurity, with a doubled-letter 'ssecurity' lure and three hyphens on .top) matches generic cloud/security-themed phishing infrastructure naming rather than any real brand, so it warrants watching but not a phishing call.

First passlooks benignconfidence 95%· claude-haiku-4-5

The page is Porkbun's standard expired-domain placeholder showing the registrar's own branding and messaging. Despite the domain name containing brand-adjacent words (cloud, security) and typo-like construction, the actual page content is the hosting provider's boilerplate notice, not a phishing page impersonating any organisation. No credentials form or deceptive content is present.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Tuesday, September 1, 2026

Screenshot of yl-cloud-web-ssecurity.top taken by the zone census on 2026-09-01

Same data as JSON: /api/zone/domain/yl-cloud-web-ssecurity.top. This page is not indexed by search engines and does not link to the site it describes.