secure-authaccount[.]com
“403 Forbidden”
Evidence Summary
As of July 23, 2026, the domain secure-authaccount.com is flagged for credential phishing and is currently offline. The domain appears on one security blocklist, specifically the PhishDestroy list, and has a Gridinsoft trust score of 0/100, indicating a highly untrusted site. It was registered through Metaregistrar BV on December 02, 2025. The nameservers used are ns1.1domainregistry.com, ns2.1domainregistry.com, ns3.1domainregistry.com, and ns4.1domainregistry.com.
The domain resolves to the IP address 20.215.32.24, which is located in Poland and is associated with Microsoft Corporation's ASN (AS8075). The current HTTP status of the site is 403 Forbidden, which suggests that the server is refusing to respond to requests, possibly due to the domain being taken offline or blocked. Analysis indicates that 13 out of 95 security vendors on VirusTotal have flagged this domain, and it has been referenced in one threat intelligence pulse on AlienVault OTX.
Given the elevated risk level and the lack of an SSL certificate, defenders should treat any past or future activity on this domain with high caution. It is recommended to monitor for any signs of the domain coming back online and to ensure that users are aware of the credential phishing threat associated with this domain. Defenders should also consider implementing additional security measures, such as DNS-based blocking and user education, to mitigate potential risks.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive