spotify[.]servernotification[.]events
“Login - Spotify”
Stored observation
Observed title contrast
Evidence Summary
The domain spotify.servernotification.events hosted a page titled "Login - Spotify" and is classified as an impersonation scam. The site was designed to mimic the Spotify login interface to deceive users into entering credentials. Although the page title references Spotify, the site impersonates the Google brand, indicating a targeted phishing attempt to harvest Google account credentials.
Technical analysis reveals the site was flagged by 20 of 95 VirusTotal vendors, with detections from ADMINUSLabs, BitDefender, Certego, Chong Lua Dao, and Cluster25. Google Safe Browsing flagged the site for social engineering. The domain was registered through NameCheap, Inc., hosted on IP address 3.174.46.79 (Germany) assigned to AS16509 Amazon.com, Inc., and used an Amazon RSA 2048 M02 SSL certificate. Nameservers were provided by Amazon Web Services.
The site is currently down/offline. GridinSoft trust rating is 0 out of 100, and the DOM risk score is 83, indicating a high-risk threat. Despite being offline, the domain remains a significant risk due to its association with credential theft and impersonation of trusted brands.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Registration: servernotification.events
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain servernotification.events behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive