Phishing detection: autoconfig.uspsecuredlogs.com
USPS Investigate
Domain
autoconfig.uspsecuredlogs.com13 CT hosts on apex
IP
207.210.229.232
URL
https://autoconfig.uspsecuredlogs.com
Cert
YR1
Phishunt analysis Beta
40
high suspicion likely_phishingheuristic risk score · not a probability
Why?
- +6.1 Google Safe Browsing
- +5.3 Keyword match
- +5.1 Site cluster
- +3.7 Brand in domain label
- +3.5 ASN reputation
- +3.4 Cert reuse
- +3.4 Shared IP cluster
- +3.2 Young domain
- +1.1 No CSP header
- +0.9 No registrar lock
- +0.7 Brand in cert SAN
- +0.7 Unrecognised DNS provider
- +0.6 Long domain
- +0.6 Login text in screenshot
- +0.6 Registrar reputation
- +0.5 Young certificate
- +0.3 Free CA
- +0.2 Suspicious TLD
- +0.1 Deep subdomain
22 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates USPS using an autoconfig-themed subdomain, suggesting email client configuration phishing. Hosted on the same fraudulent domain as other USPS phishing pages and flagged by Google Safe Browsing as social engineering.
Brand in domain labelGoogle Safe BrowsingNo registrar lock
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-14 · confidence 78%
Domain & Network
Whois
Registrar
Neubox Internet S.A. de C.V.
Network
Country
United States
Hosting
TierPoint, LLC
ASN
AS17378
TLS Cert
YR1
External detection
Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise