This domain, edf-espace-client.co, is actively flagged as a high-risk phishing site targeting EDF client portal credentials. Registered on May 15, 2026, through Dynadot Inc, the domain remains operational as of July 31, 2026, with no evidence of takedown or suspension. Infrastructure analysis reveals Cloudflare nameservers (kara.ns.cloudflare.com, zahir.ns.cloudflare.com) and resolution to IP 188.114.96.3, a Cloudflare proxy address commonly used to obscure hosting origins. Detection data is limited but indicative: one security vendor on VirusTotal flags the domain, and it appears on the PhishDestroy blocklist.
No additional brand-specific indicators, phishing kit signatures, or HTTP response details are currently available in public feeds. Defenders should treat this domain as a confirmed phishing threat targeting EDF customers. Immediate action includes blocking the domain at DNS and web proxy layers, monitoring for credential theft attempts linked to this infrastructure, and alerting EDF security teams for potential brand abuse.
Given the use of Cloudflare, defenders may encounter challenges in identifying the true hosting provider or origin server. If internal logs show user interaction with this domain, initiate password resets and multi-factor authentication reviews for affected accounts. Further analysis of SSL certificates, HTTP headers, or captured page content may provide additional indicators, but current evidence supports high-risk classification based on registration pattern, nameserver configuration, and blocklist presence.