Phishing detection: dhl-express-ujyvsooevupfoouanmmsotzq.pages.dev

DHL
https://dhl-express-ujyvsooevupfoouanmmsotzq.pages.dev Access site
Screenshot
No screenshot available yet Captured automatically on the next refresh cycle
Investigate
Domain dhl-express-ujyvsooevupfoouanmmsotzq.pages.dev1 CT host on apex
URL https://dhl-express-ujyvsooevupfoouanmmsotzq.pages.dev
Cert Let's Encrypt
Phishunt analysis Beta
29 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +5.1 urlscan.io
  • +3.4 Shared IP cluster
  • +2.2 Country mismatch
  • +2.0 Young domain
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.7 Brand in cert SAN
  • +0.6 Long domain
  • +0.6 Suspicious TLD
  • +0.3 Free CA
  • +0.2 Hyphens
  • +0.2 Obfuscated JavaScript
  • +0.1 Deep subdomain
20 signals fired · detector v3.0.0
AI analysis AIBeta
Delivery scam

Site impersonates DHL Express using a randomly generated subdomain on Cloudflare Pages. No legitimate DHL outlinks detected and security headers are absent. Flagged malicious by urlscan, consistent with delivery phishing harvesting personal or payment data.

PaaS hosturlscan.ioKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-20 · confidence 82%
Domain & Network
Whois
Registrar CloudFlare, Inc.
Network
Country United StatesUnited States
ASN AS13335
TLS Cert Let's Encrypt
External detection urlscan.io
CleanGoogle Safe Browsing · OpenPhish · PhishTank · TweetFeed
Report this phishing
PaaS platform Cloudflare Pages
Registrar CloudFlare, Inc.

Tracked from 2026-08-20 06:38 UTC  ·  Last refreshed 2026-08-24 15:30 UTC