workplace.zohomail.support
Category: Malicious
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of workplace.zohomail.support
The domain workplace.zohomail.support appears to present itself as a Zoho-related billing or account-services page. Based on the screenshot, it displays Zoho branding and asks visitors to complete a transaction to reactivate services by entering payment-card details for a "Workplace Professional Plan." The page appears focused on subscription renewal or payment collection rather than general informational content.
The domain structure is notable because it uses the .support top-level domain and places "zohomail" within a subdomain rather than using a clearly established primary Zoho corporate domain. While the page visually resembles a software-service payment portal, the available data suggests this is a very newly created standalone domain rather than a long-established official customer portal. That combination may be relevant when assessing authenticity.
Safety Assessment for workplace.zohomail.support
This website raises several caution signals based on the available scan data and visible page content. It was flagged by 1 out of 91 security engines at the time of this scan, while malware scanning did not identify malicious files and major threat databases were otherwise clean. However, the domain is only 3 days old, has no established traffic ranking, and the screenshot shows a payment form requesting full card details under Zoho branding.
The more significant concern is that the domain appears to closely imitate Zoho branding while using a separate domain name, which may indicate a look-alike payment or account-reactivation page rather than an official service endpoint. Newly registered domains that request billing information can carry elevated phishing risk even when broad blacklist coverage is still limited, because reputation systems may lag behind newly deployed pages.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was using a valid Let's Encrypt SSL certificate at the time of this scan, served over an nginx web server from an IP hosted with DigitalOcean in Singapore. A valid certificate helps encrypt traffic in transit, but it does not by itself confirm that the operator or payment page is legitimate.
DNSSEC appears to be unsigned, and the domain uses Cloudflare nameservers. The infrastructure is fairly typical for quickly deployed web content, but the combination of very recent registration, generic cloud hosting, and a payment-collection page presented under brand-like wording may warrant additional scrutiny.
Share your experience with this website. Was it safe? Did you encounter any issues?