webmail-service-xfinity.gercel.app
Category: Phishing
- Don't sign in or pay here. Close it. If you typed a password, change it where you normally use it.
- Already visited? Check your device. A free scan shows whether anything was installed.
- Stop the next one. Combo Cleaner's web protection blocks phishing and scam sites before they load.
Combo Cleaner is PCrisk's own anti-malware tool, owned by RCS LT. Free to scan; removing what it finds needs a licence (7-day free trial).
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of webmail-service-xfinity.gercel.app
This domain appears to present a login page branded as Xfinity, with the page title "Xfinity Login" and a screenshot showing a sign-in form for an "Xfinity ID." The visible layout imitates a telecommunications customer portal, including links such as account recovery and account creation, and branding associated with Comcast's Xfinity service.
Based on the domain name, however, this does not appear to be an official Xfinity-owned web address. Instead, it is hosted on a third-party subdomain under gercel.app and references the legitimate login.xfinity.com domain in its page resources and scan findings. That combination suggests the page may be attempting to resemble a real customer login experience rather than operating as an official service portal.
Safety Assessment for webmail-service-xfinity.gercel.app
The scan results indicate multiple risk signals at the time of this scan. The domain was flagged by 11 out of 91 security engines, with several classifying it as phishing or malicious, and it was also listed by a major threat database for social-engineering activity. In addition, blacklist checks showed listings related to phishing or malicious behavior, and the page content closely resembles Xfinity's real sign-in experience while using a different domain name.
The domain name itself closely resembles an Xfinity-related webmail or account service and may be a look-alike intended to capture user credentials. The screenshot, page title, and the presence of a referenced legitimate Xfinity login URL all reinforce the possibility that this page is imitating a known brand login flow. A DNS-based mail-reputation listing was also present for the IP address, although that signal is weaker than the phishing detections and content-based listings.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was set to expire on 2026-12-23. It appears to be hosted on Vercel infrastructure, using the nameservers ns1.vercel-dns.com and ns2.vercel-dns.com, with the server IP resolving to 64.239.123.65 in the United States. DNSSEC was not enabled.
From a technical risk perspective, the use of valid TLS does not by itself indicate legitimacy, since phishing pages commonly use free certificates as well. The combination of third-party hosting, an unsigned DNSSEC configuration, suspicious JavaScript flagged during scanning, and a login page visually aligned with a well-known brand but served from an unrelated domain may be consistent with credential-harvesting infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?