The domain amlservice.click was registered on July 23, 2026 through TUCOWS.COM, CO. It is delegated to Cloudflare nameservers beth.ns.cloudflare.com and roman.ns.cloudflare.com, indicating the use of Cloudflare's DNS and possibly its CDN services. DNS resolution points to IP address 188.114.97.3, an address known to belong to Cloudflare's network, which can obscure the true hosting location and complicate takedown actions. The domain appears on one public security blocklist and has been added to the PhishDestroy blocklist, suggesting that at least one security community has identified it as malicious.
VirusTotal reports that the URL was scanned by 91 antivirus and URL‑reputation engines, none of which flagged the site at the time of scanning; however, the absence of detections does not constitute a safety assurance. No public page title, SSL certificate details, or HTTP response codes are available in the current intelligence, and no brand or specific lure has been identified. Consequently, the precise phishing theme and any credential‑harvesting pages remain unknown. Defenders should treat amlservice.click as a high‑confidence indicator of phishing activity.
Recommended mitigations include adding the domain to DNS‑level blocklists, updating web‑proxy and secure web‑gateway policies to deny or sandbox traffic to the host, and monitoring email gateways for messages that reference the domain or similar URL patterns. Continuous threat‑intel feeds should be consulted for any emerging observations, such as newly discovered page content, additional blocklist listings, or shifts in the hosting infrastructure. Incident response teams should be prepared to collect forensic artifacts should user interaction occur, and threat‑hunting queries should incorporate the domain and its resolving IP to uncover related activity within the network.