Analysis indicates that the domain swiftyl.netlify.app is currently active and has been classified as a generic phishing site with a high risk rating. The domain is hosted on Netlify, as indicated by the registrar information, and resolves to the IPv4 address 63.176.8.218. Netlify’s infrastructure typically assigns shared IP ranges, and the presence of this IP does not alone confirm malicious intent, but the aggregation of other indicators strengthens the suspicion. The domain’s authoritative name server lookup failed, returning NS_NOT_FOUND, which is a common tactic to obscure DNS configuration and impede automated reputation checks.
The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy service, demonstrating that at least one trusted anti‑phishing feed has identified it as malicious. VirusTotal analysis shows that six of ninety‑one scanning engines have raised detections against the domain, providing independent corroboration of malicious behavior. No additional contextual data such as page title, SSL certificate details, or HTTP response codes are available, leaving the content of the site unrevealed. Consequently, the primary evidence consists of hosting attribution, DNS anomalies, blocklist inclusion, and multi‑vendor detections.
Defenders should prioritize adding swiftyl.netlify.app to outbound filtering rules, enforce DNS sinkholing where feasible, and monitor network traffic for connections to the IP address 63.176.8.218. Because the domain is hosted on a popular static‑site platform, legitimate services may share the same IP range; therefore, correlation with other indicators such as user‑agent strings, request patterns, or credential‑theft attempts is recommended to reduce false positives. Continuous re‑evaluation is advised, as the domain remains active and could evolve its tactics.