nansenmagazine[.]com
“Instagram”
Evidence Summary
The domain nansenmagazine.com was registered on 21 February 2026 through Tucows Domains Inc. and is actively serving content that mimics the Instagram brand. The site’s HTML title is set to “Instagram”, a clear indicator of brand impersonation. The domain is listed on a public security blocklist and is currently flagged by PhishDestroy as an active impersonation threat.
Infrastructure analysis shows the site presents a TLS certificate issued by Let’s Encrypt (YR1) while also reporting DigiCert in the technology fingerprint, suggesting a possible certificate chain substitution. HSTS and HTTP/3 are enabled, and the site issues an HTTP 301 redirect to the same host. DNS resolution points to IP address 198.49.23.145, which belongs to a US‑based Squarespace hosting environment. Authoritative name servers are dns1.p02.nsone.net through dns4.p02.nsone.net.
Reputation metrics reinforce the malicious profile. Gridinsoft assigns a trust score of 0 out of 100, indicating a high likelihood of abuse. VirusTotal analysis records 2 out of 95 security vendors flagging the domain, and the domain appears on at least one additional blocklist. Combined with the brand‑specific page title and the 301 redirect, these indicators confirm the site is designed to lure Instagram users.
Defenders should add nansenmagazine.com to URL filtering and sinkhole lists, enforce TLS inspection to capture the redirect behavior, and monitor DNS queries to the nsone.net name servers for similar patterns. Continuous re‑evaluation is advised, as the domain’s short age and recent registration suggest it may be part of a broader impersonation campaign targeting Instagram users.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of nansenmagazine.com · checked Mar 2, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive