Analysis of checkfn.com shows that the domain was registered on July 23 2026 through Dominet (HK) Limited. The authoritative name servers are a.dnspod.com, b.dnspod.com and c.dnspod.com, which are commonly used by fast‑flux or bulk‑registration services. DNS resolution points to the IPv4 address 193.187.110.3; the host appears to be currently reachable and is listed as active by monitoring feeds.
The domain is already listed on one public security blocklist and has been flagged by the PhishDestroy sink‑hole as malicious. VirusTotal reports indicate that the domain was submitted to 91 scanning engines, none of which returned a detection at the time of analysis; the absence of a detection does not constitute evidence of benign intent. No additional metadata such as SSL certificate details, HTTP response codes, page title, or known phishing kit identifiers are available in the supplied intelligence.
Consequently, the confidence in the phishing classification rests on the blocklist entry and the PhishDestroy designation, both of which are typical indicators of credential‑harvesting infrastructure. Defenders should consider adding 193.187.110.3 and the associated hostnames to network‑level deny lists, enforce outbound DNS filtering for the dnspod.com name servers, and monitor for any new observations that reference checkfn.com. Ongoing collection of HTTP and payload samples is recommended to confirm the payload and to enrich future attribution efforts.