auth-telekom.de
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of auth-telekom.de
The domain auth-telekom.de appears to present itself as a Telekom login page, using Telekom branding, a "Telekom Login" title, and a sign-in form in German. The page layout and linked references suggest it is attempting to resemble an account-access portal for Deutsche Telekom users, with links pointing to legitimate Telekom-related pages such as help, privacy, and login resources.
However, the domain itself is not the primary Telekom domain shown in the page links, and the naming pattern "auth-telekom.de" may be intended to look related to the brand while remaining separate from the official web properties. Based on the screenshot and metadata, the site appears focused on credential entry rather than broader customer services or normal corporate content.
No clear operator identity is established from the scan data beyond the branding shown on the page. In practical terms, this appears to be a login-themed website imitating a telecommunications customer account portal rather than a full standalone business website.
Safety Assessment for auth-telekom.de
This domain shows multiple high-risk indicators at the time of this scan. It was flagged by 20 out of 91 security engines, with many classifying it as phishing or malicious, and it is also listed by phishing-focused threat databases. The page closely resembles a Telekom login experience while using a separate domain, which may indicate a look-alike site intended to capture account credentials. The domain was created very recently, has no established traffic ranking, and presents a single-purpose login form, all of which are common warning signs in phishing investigations.
The malware scan did not report confirmed malicious files, but it did attach a generic suspicious heuristic to the domain and several internal resources. That kind of heuristic alone would be low-confidence, but here it is outweighed by the broader multi-engine phishing consensus and the page's apparent imitation of a known brand login flow. In addition, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal on its own but still adds minor caution.
Based on these findings, this website may pose potential risks to visitors, particularly anyone asked to enter account credentials or personal information.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by Sectigo Limited, expiring on 2027-01-06. A valid certificate helps encrypt traffic in transit, but it does not by itself confirm that the site is legitimate. The server appears to run Apache on an IP associated with hosting infrastructure in Essen, Germany, and the nameservers point to web.de-operated DNS services.
From a domain-security perspective, the domain is extremely new, with a creation date of 2026-07-12, and DNSSEC appears to be unsigned. The combination of a newly registered domain, brand-themed login content, and phishing detections across multiple security engines is a notable technical concern at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?