ScamLens analyzed reims35.com using 90+ threat intelligence sources and assigned a trust score of 46/100, classifying it as moderate risk.
Trust Score: 46/100
Risk Level: Caution
This result is still in the investigation range, so the domain alone is not enough for a decision. The next step is to cross-check the email, phone number, company identity, and scenario.
Quick Answer
This result is still in the investigation range, so the domain alone is not enough for a decision. The next step is to cross-check the email, phone number, company identity, and scenario.
Positive Signals
- + Google Safe Browsing: Safe
- + HTTPS encryption supported
Concerns
- - Domain registered only 1 month ago
- - 2 security sources flagged as suspicious
Score Breakdown
Was this assessment accurate?
Mixed signals on reims35.com
We did not find direct threat-feed hits, but coverage is thin or other signals warrant care.
- Verify the company exists offlineSearch the registered company name + 'reviews' or 'scam'. Real businesses leave a long trail of independent mentions.
- Pay only via reversible methodsUse credit cards or PayPal Goods & Services. Avoid wire transfers, crypto, gift cards — those are non-reversible.
- Confirm the contact detailsLook up the phone number and email address separately. Free webmail addresses or VoIP numbers are a red flag.
Trust but verify — open this domain on unrelated security services and compare the verdict.
AI Risk Assessment
Moderate RiskWhat matters right now
This is the easiest range to misread. Do not rely on the domain alone. Cross-check the email, phone number, company identity, and transaction context together.
reims35.com shows conflicting signals. [FACT] Safe Browsing is clean 1 and 25 of 27 threat feeds responded clean 3, suggesting no confirmed malicious activity. However, [FACT] VirusTotal and Shodan Internet DB have flagged this domain for phishing and suspicious ports respectively 2. [FACT] The domain is 32 days old 4, placing it in the moderately suspicious window (under 30 days is higher risk, but 32 days still warrants caution). [FACT] The .com TLD carries low intrinsic risk 5. [INFERENCE] The phishing flag from VirusTotal is the primary concern—this suggests potential credential harvesting or fraud targeting, despite Safe Browsing missing it. Suspicious port exposure on Shodan may indicate infrastructure misconfigurations that could be exploited. Together, these two signals from established threat sources outweigh the clean responses from most feeds. [FACT] No brand impersonation or homograph attacks detected 2. [UNVERIFIED] The registrar CNOBIN INFORMATION TECHNOLOGY LIMITED's reputation and the specific phishing/port details from flagged feeds are not fully detailed in available data.
Recommendation
Treat with caution. Do not enter credentials or download files. [INFERENCE] The VirusTotal phishing flag warrants verification—manually check the domain owner's legitimacy through independent channels before engaging. If this is a personal or business domain under your control, investigate the Shodan port findings and audit your server configuration for exposure. Request detailed threat intelligence reports from VirusTotal and Shodan to confirm the specific phishing vectors and port vulnerabilities. Monitor for community reports; as this domain ages, additional user feedback will clarify intent. If the domain is unfamiliar to you, avoid it entirely.
Sources
- Threat intelligence feeds (2 flagged)Threat intel
virustotal (PHISHING); shodan_internetdb (SUSPICIOUS_PORTS)
- 25/27 threat feeds responded cleanThreat intel
- WHOIS registration dataWHOIS
Registered 2026-05-08T10:19:56Z (32 days ago), registrar: CNOBIN INFORMATION TECHNOLOGY LIMITED
- TLD risk classification: .com (low risk)Analysis
Based on APWG / Spamhaus / Interisle 2024 abuse rankings
Powered by ScamLens AI· Check sources to verify important claims
Threat-intelligence sources
Checked across 27 sources — 2 flagged this domain
Show source breakdown
Threat-intelligence sources
Checked across 27 sources — 2 flagged this domain
- safe_browsing clean
- urlhaus clean
- cloudflare_radar clean
- cert_transparency clean
- alienvault_otx clean
- phishstats clean
- virustotal flagged
- ipqs clean
- abuseipdb clean
- securitytrails clean
- phishdestroy clean
- threatfox clean
- shodan_internetdb flagged
- phishtank clean
- urlscan clean
- rdap clean
- maltiverse clean
- dns_security clean
- wanted_domains clean
- darkweb clean
- openphish clean
- scam_blocklist clean
- maltrail clean
- crypto_scam_feed clean
- phishing_army clean
- hagezi_tif clean
- red_flag_domains clean
ScamLens aggregates real-time signals from 90+ commercial and open-source threat-intelligence providers including Google Safe Browsing, VirusTotal, PhishTank, URLhaus, ThreatFox, Cloudflare Radar, OTX, IPQS, GoPlus, Honeypot.is, and more. A flagged signal is evidence; the absence of flags is not proof of safety. Use the signals below alongside community reports to decide.
Advanced Scan
Comprehensive data lookup across premium sources
- Website history verification
- Detailed WHOIS information
- Reverse WHOIS association
- Traffic rank analysis
- Company registration check
AI Deep Investigation
Cross-check the story, claims, and supporting evidence before you decide
- Everything in Advanced Scan
- AI website content analysis
- AI cross-reference verification
- Claim authenticity validation
- Detailed report with evidence
Comprehensive Investigation
Full-spectrum investigation with company deep search & social intelligence
- Everything in Deep Investigation
- AI company background search
- Social media intelligence
- Detailed suspicious point analysis
- Event timeline & entity connections
This analysis is for informational purposes only and does not constitute a legal determination.
Security Sources
Domain Information
- Registrar
- CNOBIN INFORMATION TECHNOLOGY LIMITED
- Created
- May 8, 2026
- Expires
- May 8, 2027
- Domain Age
- 1 months
- DNSSEC
- Disabled
- Nameservers
- JASPER.NS.CLOUDFLARE.COM, MINA.NS.CLOUDFLARE.COM
- Domain Status
- client transfer prohibited
SSL/TLS Certificate
No data available
Server Information
- IP Address
- 172.67.131.214
- Hosting Provider
- Cloudflare, Inc.
- ASN
- AS13335 Cloudflare, Inc.
- Server Location
- Toronto, Canada
- Organization
- Cloudflare, Inc.
Related Intelligence
Technical Details (DNS / Headers / Subdomains)
DNS Records
Email Security
SPF Not Configured DMARC Not Configured| Type | Value |
|---|---|
| A | 172.67.131.214 |
| A | 104.21.11.240 |
| AAAA | 2606:4700:3032::6815:bf0 |
| AAAA | 2606:4700:3033::ac43:83d6 |
| NS | jasper.ns.cloudflare.com |
| NS | mina.ns.cloudflare.com |
HTTP Security Headers
Channels / Subdomains
No data available
Community Reports
Log in to report and share your experience
Report & Take Down This Website
Continue Investigating
The result is still in the investigation range. Cross-check the email, phone, and entity data next
Medium-risk domains are easiest to misread when you only check one signal. The decision gets more reliable once you cross-check the email, phone number, company identity, and business scenario together.
Recommended First
Analyze the related email or invoice
Confirm whether the billing notice, restriction alert, or support email actually matches the site.
Check the company or seller identity
Compare the domain against the company identity, merchant profile, or hiring details.
Check the related phone number
If the actor wants a callback, phone verification, or one-time code readout, verify that number next.
Open the matching scenario guide
If the case involves investing, shopping, or recovery services, verify it through the matching scenario guide.
The results are based on multiple third-party data sources and AI models. False positives or negatives may occur. This report should not be used as the sole basis for any decision. Please verify with additional sources.
Verify the related evidence objects first
Medium-risk cases are easiest to misread when you only check one signal. Verify the email, phone, and entity before deciding whether to report or stop the transaction.
If you already paid or exposed account access, skip the investigation loop and move into the action plan.
Related Security Guides
Learn more about how to protect yourself from this type of threat.
Understanding this threat
FAQ
Is reims35.com safe to visit?
reims35.com received a trust score of 46/100 from ScamLens. Some minor concerns were identified but no critical threats were found. Exercise normal caution.
Was reims35.com flagged by any threat databases?
reims35.com was flagged by 1 out of 30+ threat intelligence sources. Specifically flagged by: virustotal. The detected threat categories include: general threat.
How old is reims35.com?
reims35.com was first registered on May 8, 2026, making it approximately 1 month old. While relatively new, the domain has been active for several months.
Does reims35.com use HTTPS and have a valid SSL certificate?
ScamLens could not verify the SSL certificate details for reims35.com during this scan. Treat this as unavailable evidence, not as proof that the site is safe or unsafe.
What security headers does reims35.com implement?
No security header information was available for reims35.com.
What does the ScamLens community think about reims35.com?
No community votes or reports have been submitted for reims35.com yet. You can be the first to share your experience.
Where is reims35.com hosted?
reims35.com is hosted by Cloudflare, Inc. in Toronto, Canada (ASN: ASAS13335 Cloudflare, Inc.).
What should I do about reims35.com?
Treat with caution. Do not enter credentials or download files. [INFERENCE] The VirusTotal phishing flag warrants verification—manually check the domain owner's legitimacy through independent channels before engaging. If this is a personal or business domain under your control, investigate the Shodan port findings and audit your server configuration for exposure. Request detailed threat intelligence reports from VirusTotal and Shodan to confirm the specific phishing vectors and port vulnerabilities. Monitor for community reports; as this domain ages, additional user feedback will clarify intent. If the domain is unfamiliar to you, avoid it entirely.
Is this report useful?
Use this report to prompt others to keep cross-checking the email, phone number, and entity details instead of clearing it too early.
Forward to your parents — they deserve to browse safely too.
About this analysis
This report is generated from real-time data across 90+ threat intelligence sources, combined with AI analysis and community feedback.
Learn about our scoring methodology | Last analyzed: June 10, 2026
All CNOBIN INFORMATION TECHNOLOGY LIMITED domains All Cloudflare, Inc. domains