Analysis of fortlock.top as of 31 July 2026 indicates that the domain is actively used in a generic phishing operation. The domain was registered on 20 December 2025 through PDR Ltd. d/b/a PublicDomainRegistry.com and remains active. DNS resolution points to the IPv4 address 158.94.211.169, hosted on infrastructure served by the DNSPod nameserver cluster (a.dnspod.com, b.dnspod.com, c.dnspod.com). VirusTotal records show that the domain has been submitted to 91 scanning engines; at the time of review none of the engines reported a detection.
The lack of detections does not constitute evidence of benign behavior, and the domain continues to appear on at least one external security blocklist. PhishDestroy, an anti‑phishing feed, has explicitly blocked the domain, reinforcing the suspicion of malicious use. No public SSL certificate details, HTTP response codes, Safe Browsing verdicts, OTX mentions, or page title information are currently available. Consequently, the full scope of the phishing payload, targeted brands, and victim interaction flow cannot be determined from the existing open‑source data.
Given the observed indicators—recent registration, dedicated DNS providers, presence on a blocklist, and inclusion in PhishDestroy’s feed—defenders should treat fortlock.top as a high‑confidence phishing indicator. Recommended actions include adding the domain to local deny lists, updating intrusion detection signatures, monitoring DNS queries for the associated IP address, and employing outbound URL filtering to block any attempted connections. Continuous re‑evaluation is advised, as future scans or threat‑intel feeds may reveal additional artifacts such as malicious payloads, SSL anomalies, or compromised credential submissions.