Analysis as of July 30 2026 identifies recruitlyon.com as an active generic phishing infrastructure. The domain was registered on July 25 2026 through the registrar Fewmoretaps OU d/b/a Trustname.com and is delegated to Cloudflare name servers guss.ns.cloudflare.com and veronica.ns.cloudflare.com. DNS resolution points to the IP address 172.67.130.83, a Cloudflare‑owned address commonly used for fast‑flux and content‑delivery services. Google Safe Browsing classifies the domain as a social‑engineering threat, and the phishing‑specific blocklist PhishDestroy has already listed it, indicating at least one security‑vendor block.
VirusTotal records show the domain was scanned by 91 antivirus and URL‑reputation vendors; none of the scanners raised a detection at the time of the scan. While the lack of detections does not constitute proof of safety, it demonstrates that the current payload or landing page has not yet triggered signatures in the surveyed engines. The domain appears on one public blocklist, reinforcing the need for defensive filtering.
Publicly available intelligence does not include a retrieved page title, SSL certificate details, HTTP response codes, or a confirmed target brand, leaving the exact phishing lure ambiguous. Consequently, defenders cannot rely on content‑based indicators such as page titles or brand keywords for detection. The observable infrastructure—recent registration, Cloudflare hosting, inclusion on PhishDestroy, and Google Safe Browsing flag—provides sufficient context for proactive mitigation.
Recommended actions: add recruitlyon.com to network and email allow‑list block rules; enforce URL filtering that references Google Safe Browsing and phishing blocklists; monitor DNS queries for the domain and its associated Cloudflare name servers; and, if feasible, retrieve the live page for deeper analysis to capture any credential‑harvesting forms or malicious redirects.