Analysis of metropalmdelivery.com indicates an active delivery scam operation with high-risk infrastructure characteristics. The domain was registered on July 18, 2026, through Ultahost, Inc., and remains operational as of July 30, 2026. It resolves to the IP address 88.222.222.123, which has not been extensively analyzed in public threat feeds at this time. Nameservers aurora.dns-parking.com and nebula.dns-parking.com are utilized, a configuration commonly observed in low-cost or automated hosting setups that may lack robust abuse controls. VirusTotal detection data shows 2 of 91 security vendors flagging the domain, suggesting emerging but not yet widespread recognition of its malicious nature.
The domain appears on one security blocklist, specifically PhishDestroy, which categorizes it as a phishing threat. No additional blocklist entries, Safe Browsing warnings, or Open Threat Exchange (OTX) pulses were identified in the available data. The exact content of the site has not been analyzed, so specific brand impersonation or scam mechanics cannot be confirmed; however, the domain name and threat classification align with delivery or courier fraud schemes. Defenders should treat this domain as high-risk based on its recent registration, limited but present detection by security vendors, and inclusion on a specialized blocklist.
Network-level blocking of the domain and its resolving IP (88.222.222.123) is recommended for organizations seeking to mitigate exposure. Further monitoring of associated infrastructure, including the nameservers and hosting provider, may reveal additional related threats. No SSL certificate or HTTP status anomalies were reported in the available intelligence, but this does not preclude the presence of malicious activity. Given the domain's active status and scam classification, continued vigilance and proactive blocking are advised until comprehensive takedown or further analysis is completed.