mail.itineraryupdate.com
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of mail.itineraryupdate.com
The subdomain mail.itineraryupdate.com appears to be an email-linked landing page rather than a general public website. Based on the visible page content, it is presenting an informational notice that says the visitor reached an authorized phishing simulation run by an organization, along with educational material about spear phishing and how to recognize suspicious emails.
The domain structure suggests it may be used for email campaign tracking, awareness training, or redirect handling connected to phishing-simulation exercises. The page does not appear to function as an online store or consumer service, and the content shown is focused on security awareness rather than commerce or account access.
Operational details are limited from the scan alone, but the domain has been registered for several years through a corporate registrar and is hosted on cloud infrastructure. That combination may be consistent with enterprise-managed campaign or training infrastructure, although the exact operator cannot be confirmed from the available data.
Safety Assessment for mail.itineraryupdate.com
Scan results show mixed signals at the time of this scan. Multiple security engines flagged the URL or domain as phishing-related, with 13 out of 91 detections, and several web-classification sources labeled it as phishing, fraud, or parked. Those findings would normally indicate elevated risk for visitors, especially because phishing-themed infrastructure often uses email-oriented subdomains such as this one.
At the same time, the visible page content appears to disclose that this was an authorized phishing simulation from an organization, and the page itself contains anti-phishing educational guidance rather than a credential-harvesting form or malware delivery content. The malware scan did not identify malicious files, and major blacklist and threat-database checks were clean at the time of this scan. This combination may indicate that some detections are reacting to the domain's use in simulated phishing campaigns rather than active criminal abuse.
Even so, users should treat unsolicited links to this subdomain cautiously unless they expect them as part of a workplace security-awareness program. Based on these findings, the website may trigger phishing-related alerts and may pose contextual risk if encountered unexpectedly, but the displayed content appears consistent with a phishing-simulation landing page at the time of this scan.
Technical Description
The site was served over HTTPS with a valid Let's Encrypt certificate that was set to expire in August 2026. It resolves to an AWS EC2 address in Sydney, Australia, and uses AWS Route 53-style nameservers. The web server software and negotiated protocol were not identified in the provided scan data.
The domain is approximately 9 years old, which is older than many short-lived phishing domains, and it is registered through MarkMonitor, a registrar commonly used for managed corporate portfolios. DNSSEC appears to be unsigned, which is not uncommon but means DNS responses do not benefit from DNSSEC validation. No malicious files, external links, or iframe activity were reported in the supplied malware-scan output.
Share your experience with this website. Was it safe? Did you encounter any issues?