New Registrations
AEAT (Hacienda) phishing domains
Newly registered lookalikes - tracked daily
AEAT (Hacienda) phishing domains
Newly registered lookalikes - tracked daily
Tracked (7d)
6
New (24h)
4
vs avg
—
Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-05-21 00:43 | 2026-05-21 00:43 | ![]() |
GSB | Details | |
| 2026-05-21 00:34 | 2026-05-21 00:34 | ![]() |
Details | ||
| 2026-05-20 01:12 | 2026-05-20 01:12 | ![]() |
Details | ||
| 2026-05-20 00:37 | 2026-05-20 00:37 | ![]() |
Details | ||
| 2026-05-17 00:35 | 2026-05-17 00:35 | ![]() |
Details | ||
| 2026-05-15 00:45 | 2026-05-15 00:45 | ![]() |
Details |
Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://dev-agenciatributaria…
GSB |
![]() |
Details |
| https://agenciatributaria-gob…
|
![]() |
Details |
| https://sede-agenciatributari…
|
![]() |
Details |
| https://agenciatributaria.biz
|
![]() |
Details |
| https://agenciatributarias.bu…
|
![]() |
Details |
| https://es-agenciatributaria.…
|
![]() |
Details |
AIHow to verify a real AEAT (Hacienda) URL
- Legitimate AEAT (Hacienda) URLs always end in
agenciatributaria.gob.es(e.g.www.agenciatributaria.gob.es,account.agenciatributaria.gob.es). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not AEAT (Hacienda). - The domains listed above were registered within the last 7 days. New-domain age is itself a signal — AEAT (Hacienda) has owned
agenciatributaria.gob.esfor years; brand-new look-alikes are almost never legitimate. - If you got the link from email, SMS, or social media, do not click it. Open
agenciatributaria.gob.esfrom your browser bookmark or type the domain manually. - Real AEAT (Hacienda) pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.





