The domain safepointfund.com is flagged as a high‑risk generic phishing site. Infrastructure analysis shows the domain was registered through Ultahost, Inc. on 30 June 2026 and is currently active. All four authoritative name servers (ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, ns4.ultahost.com) resolve the domain to the IPv4 address 173.211.81.11, which is the sole host observed in passive DNS. The hosting provider is not directly disclosed, but the IP belongs to a range commonly associated with shared hosting services. VirusTotal reports that 2 of 91 security‑vendor scanners have flagged the domain, indicating at least limited detection across the marketplace. The domain appears on one public security blocklist and has been explicitly blocked by the PhishDestroy service, confirming active mitigation by at least one anti‑phishing vendor.
No public SSL certificate details, HTTP response codes, or page‑title metadata are available in the current intelligence set, leaving the exact content and delivery mechanism of the phishing page unverified. Consequently, the precise lure or credential‑harvesting technique employed by the site cannot be confirmed at this time.
Defenders should treat safepointfund.com as malicious. Recommended actions include adding the domain and its resolving IP address to network‑level blocklists, configuring DNS filtering to deny queries for the four listed name servers, and monitoring outbound traffic for connections to 173.211.81.11. Continuous re‑scanning with multi‑engine services is advised to capture any changes to the site’s payload or hosting. Because the domain is less than two months old, rapid propagation is possible, so early containment is critical.