nowandthen[.]net[.]au
“Suspected Phishing | Cloudflare”
The domain nowandthen.net.au is confirmed to be a brand impersonation scam targeting Cloudflare. The domain was registered through Web Address Registration Pty Ltd and is currently active. Analysis reveals that the domain resolves to IP address 188.114.96.3, which is located in CA and managed by Cloudflare, Inc. The nameservers for this domain are frank.ns.cloudflare.com and ruth.ns.cloudflare.com. The SSL certificate for the domain is issued by Google Trust Services / WE1. The page title for the site is 'Suspected Phishing | Cloudflare,' indicating that the domain is being used to impersonate Cloudflare. This domain has been flagged by 4 out of 91 security vendors on VirusTotal, and it appears on 3 security blocklists. It is blocked by PhishDestroy, MetaMask, and SEAL. Given the high risk level and the active status of the domain, security professionals and users are advised to avoid interacting with this domain and to block it using available security tools. The exact content and methods used on the site have not been fully analyzed, but the infrastructure and page title strongly suggest a phishing campaign designed to deceive users into believing they are interacting with a legitimate Cloudflare service.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of nowandthen.net.au · checked Jul 20, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive