polymarket[.]verifications[.]markets
“Connect Wallet - Polymarket”
The domain polymarket.verifications.markets is identified as a high-risk brand impersonation targeting Polymarket. The domain is currently offline, but it poses a significant threat to users who may have encountered it before its takedown.
Infrastructure analysis reveals that the domain was created on February 21, 2026, and is registered through NameCheap, Inc. It resolves to the IP address 67.223.118.65, which is located in the United States and is associated with AS22612 Namecheap, Inc. The domain is protected by a Sectigo Limited SSL certificate, specifically the Sectigo Public Server Authentication CA DV R36. Google Safe Browsing has flagged the domain as a phishing site, and it appears on four security blocklists, including PhishDestroy, MetaMask, ScamSniffer, and SEAL. VirusTotal reports that 13 out of 95 security vendors have flagged this domain as malicious.
Given the current offline status, users should remain vigilant and avoid any links or communications that direct them to this domain. Security teams are advised to monitor for any resurgence of this domain or similar impersonations. Organizations and individuals should update their security configurations to block this domain and educate users about the risks of brand impersonation, particularly in the context of cryptocurrency and wallet connections. Regularly reviewing and updating phishing protection tools and DNS blocklists can help mitigate the risk of future encounters with such threats.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: verifications.markets
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain verifications.markets behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
Server-side scripting language designed for web development.
High-performance web server compatible with Apache configurations.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive