Analysis of scforty.life indicates that the domain is actively being used in a generic phishing campaign as of the report date 31 July 2026. The domain was registered on 1 May 2026 through the registrar GNAME.COM PTE. LTD. and currently resolves to the IPv4 address 193.187.110.3. DNS resolution is delegated to the authoritative nameservers a.dnspod.com, b.dnspod.com and c.dnspod.com, which are commonly associated with dynamic DNS services.
The domain appears on a single security blocklist and has been blocked by the PhishDestroy mitigation service, confirming that at least one threat‑intelligence feed has identified it as malicious. VirusTotal records show that the domain has been scanned by 91 antivirus and URL‑reputation vendors; none of the scanners have raised a detection at the time of the scan. While the lack of detections may suggest limited current visibility, it does not constitute evidence of safety, especially given the confirmed phishing classification and blocklist presence. No additional data on SSL certificates, HTTP response codes, page titles, or brand targeting is available, leaving the exact payload and victim‑targeting tactics unverified.
Consequently, the primary uncertainties revolve around the specific phishing lures employed, the geographic focus of the campaign, and any potential command‑and‑control infrastructure beyond the observed IP address. Defensive recommendations include adding scforty.life and its resolving IP 193.187.110.3 to network‑level blocklists, monitoring DNS queries for the associated dnspod nameservers, and maintaining continuous re‑scanning through multi‑vendor services to capture any future detections. Organizations should also consider implementing URL filtering policies that reference the blocklist entry and ensure that any credential‑capture attempts are routed to security awareness training programs.