MALICIOUS — CRITICAL
dpd[.]dpdccak[.]cfd
dpd.dpdccak.cfd impersonates DPD/DHL parcel delivery to steal credentials. 16/95 vendors flag it as phishing. Check the full report.
- VirusTotal
- 16/91
- Blocklists
- No stored match
- Ketersediaan
- Konten tidak tersedia · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
dpd.dpdccak.cfd — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Dpd; Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 16/91 (alphaMountain.ai, BitDefender, CRDF, Emsisoft, Fortinet); URLQuery 5 alerts; URLScan malicious verdict; Google Safe Browsing flagged; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Registrar: Dynadot.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
This domain, dpd.dpdccak.cfd, is a convincing fake designed to steal your parcel delivery login details. It mimics official DPD or DHL tracking pages, tricking you into entering your email, password, and possibly payment information. The site is currently active and poses a high risk to anyone who encounters it through phishing emails or text messages.
PhishDestroy identified this threat through multiple reliable sources. The domain was created on May 28, 2026, through Dynadot LLC, and lacks any SSL certificate, meaning data sent to it is unencrypted. VirusTotal reports that 16 out of 95 security vendors flag this domain as malicious, and Google Safe Browsing also lists it as a phishing site. It resolves to IP address 43.165.0.236 and appears on one security blocklist, confirming its dangerous nature.
If you have already visited this site and entered any personal information, change your passwords immediately and enable two-factor authentication on your accounts. Monitor your financial accounts for unauthorized transactions and report any suspicious activity to your bank. To stay safe, always verify the legitimacy of delivery notifications by visiting the official carrier website directly, rather than clicking links in unsolicited messages.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | dpd.dpdccak.cfd |
malicious | Sinkholed |
| OpenDNS | dpd.dpdccak.cfd |
phishing | Phishing Block |
| DigiCert UltraDNS | dpd.dpdccak.cfd |
malicious | Sinkholed |
| Quad9 DNS | dpd.dpdccak.cfd |
malicious | Sinkholed |
| DNS4EU | dpd.dpdccak.cfd |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ZONA SHORTDOT · BUKTI PUBLIK
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: dpdccak.cfd
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain dpdccak.cfd behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Keyakinan 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Keyakinan 100%Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260530-F057B0 Recipient: abuse@tencent.com Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.