smtptelstrawebmailswiftviewtelstrawebmailswiftwebmail[.]framer[.]website
“Sign in with your Telstra ID”
Analysis of the domain smtptelstrawebmailswiftviewtelstrawebmailswiftwebmail.framer.website shows an active brand‑impersonation infrastructure that was taken offline prior to the report date of July 24, 2026. The domain was registered on November 19, 2021 through CSC Corporate Domains, Inc. and is hosted on Amazon Web Services, resolving to the IPv4 address 52.223.52.2, which belongs to AS16509 (Amazon.com, Inc.) and is geolocated in the United States. An SSL certificate issued by Let’s Encrypt (certificate identifier E7) was present, and the site advertised modern web technologies including Framer Sites, React, HTTP Strict Transport Security (HSTS) and HTTP/3 support. An HTTP request to the site returned a 404 status code, indicating that the landing page is no longer publicly reachable.
VirusTotal scans recorded 13 detections out of 95 security vendors, and the domain appears on a single public blocklist. PhishDestroy has also listed the domain as blocked. The page title observed during the brief capture phase was "Sign in with your Telstra ID," confirming the impersonation of Telstra and the credential‑phishing intent. Nameservers listed are ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com and ns-792.awsdns, consistent with AWS DNS hosting.
While the site is currently offline, the persistence of the underlying AWS infrastructure and the reuse of the same certificate suggest the possibility of future reactivation. Defenders should add the IP address 52.223.52.2 to network deny lists, monitor DNS queries for the associated subdomains, and update email security gateways to block messages referencing the observed page title or the Telstra brand. Continuous surveillance of the registrar and blocklist entries is recommended to detect any re‑registration attempts or new hosting signatures tied to this campaign.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Technologies · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive