mail-jdhlilinlink[.]appwrite[.]network
“Sign In.”
Evidence Summary
This domain, mail-jdhlilinlink.appwrite.network, poses a credential harvesting threat by impersonating DHL, a global logistics provider. Visitors to the site encounter a fraudulent login page titled 'Sign In,' designed to deceive users into submitting sensitive account details such as usernames, passwords, or shipment tracking credentials. The site exploits trust in the DHL brand to facilitate unauthorized access to personal or corporate data, potentially leading to financial fraud or identity theft. Analysis indicates the domain was registered on March 12, 2026, through the Appwrite registrar and resolves to the IP address 151.101.131.52, hosted on infrastructure belonging to AS54113 (Fastly, Inc.) in the United States. The SSL certificate is issued by Certainly, a provider commonly used for both legitimate and malicious domains. Detection engines on VirusTotal flagged the domain as malicious, with 20 out of 95 security vendors identifying it as a phishing site. Additionally, the domain appears on one security blocklist, further confirming its malicious intent. If you or someone in your organization visited mail-jdhlilinlink.appwrite.network and entered credentials, immediate action is required. First, reset the password for any accounts accessed through the site, using a strong, unique password not reused elsewhere. Enable multi-factor authentication where available to add an extra layer of security. Monitor accounts for unauthorized activity, such as unexpected shipments, password changes, or financial transactions. If payment details were submitted, contact your financial institution to report potential fraud and request a card replacement. Finally, report the incident to your organization’s IT or security team for further investigation and mitigation.
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | mail-jdhlilinlink.appwrite.network/ |
malware | Detects file containing Telegram Bot API |
| YARAhub by abuse.ch | mail-jdhlilinlink.appwrite.network/favicon.ico |
malware | Detects file containing Telegram Bot API |
| Cloudflare DNS | mail-jdhlilinlink.appwrite.network |
malicious | Sinkholed |
| OpenDNS | mail-jdhlilinlink.appwrite.network |
phishing | Phishing Block |
| DNS4EU | mail-jdhlilinlink.appwrite.network |
malicious | Sinkholed |
| Hagezi Threat Feed | mail-jdhlilinlink.appwrite.network |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Registration: appwrite.network
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain appwrite.network behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of mail-jdhlilinlink.appwrite.network · checked Apr 23, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive