gov-dwpqtp[.]top
Analysis of the domain gov-dwpqtp.top indicates a high‑risk, active phishing infrastructure. The domain was registered on June 12, 2026 through 阿里云计算有限公司 (Alibaba Cloud), a registrar frequently leveraged by threat actors to obtain disposable hosting. VirusTotal reports that 14 of 91 security vendors have flagged the domain, demonstrating a measurable consensus among detection engines that the site is malicious.
Google Safe Browsing classifies the URL as a social engineering threat, and the domain appears on a security blocklist as well as being blocked by the PhishDestroy service, confirming its inclusion in multiple defensive feeds. The cumulative evidence places the domain in the high‑risk category and aligns with the generic phishing threat type supplied. No public data on the hosting IP, SSL certificate details, HTTP response codes, or page title have been released, leaving those aspects of the infrastructure unverified.
Defenders should immediately add gov-dwpqtp.top to DNS‑based blocklists and firewall deny rules, ensure that web‑proxy and email security solutions reference the latest Google Safe Browsing and PhishDestroy feeds, and monitor for any outbound connections to the registrar’s network ranges. Continuous re‑evaluation is advised, as additional indicators such as hosting metadata or payload samples may emerge, potentially expanding the scope of associated malicious activity.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive