Is dnmx.cc legit or a scam?
High-risk dark-net email relay with a history of police seizures, criminal use in bomb threats, and active malicious detections by our antivirus network.
These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.
Analysis Summary
Phishing site — do not log in
A Google login is shown on an unrelated domain — classic credential-harvest pattern. This page looks designed to steal credentials. Don't log in — and if you already did, change the password anywhere you reused it and turn on two-factor authentication.
Website Preview

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site. See full visual analysis →
Visual Screenshot Analysis
We capture a fresh screenshot of the live page and ask a vision model to look for scam visual patterns — fake trust badges, countdown timers, overlay pop-ups, and visual clones of legitimate brands.
Visual red flags detected in the screenshot
The site presents as a dark-net-adjacent email provider; while the layout is functional, the subject matter and domain-hopping notice are typical of high-risk or grey-market services.
What our vision model saw
6 signalsExplicit reference to 'Dark Net' services and onion addresses
Banner notification indicating a domain change from .su to .cc
Login form with a low-quality, custom captcha implementation
Promotes anonymous email services which are frequently associated with high-risk activities
Minimalist design with limited corporate or legal information
Language selection includes Russian and German alongside English
Brand Impersonation
medium confidenceThe page mentions or styles itself as Google, but is hosted on a domain that is not an official Google property. A login form was also detected — this combination is a classic credential-harvest setup.
MT Intelligence
Our analysis identifies this site as a dangerous gateway for anonymous communication frequently used by threat actors. The domain is a direct successor to a previous version that was seized by Dutch police in 2023 due to its role in narcotics and terrorist communications. Three of our antivirus partners, including Chong Lua Dao and CRDF, explicitly flag the site as malicious. We also detected a credential-harvesting pattern where the login form mimics official service layouts to capture user data. The operator's own disclaimer warns users not to trust the service, which is a significant red flag for any legitimate provider.
Web Research Findings
Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for dnmx.cc, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.
- dnmx.cc is the clearnet site for Dark Net Mail Exchange (DNMX), an anonymous Tor-only email service that relays to clearnet; onion address provided on site.
- Domain registered July 15, 2025 (approx. 11-12 months old as of mid-2026); previously operated as dnmx.su which was seized by Dutch police in October 2023.
- Forbes reported in 2025 that DNMX was used for CSAM, terrorism, and narcotics; police seized servers and accessed user emails; admin note indicated accounts "no longer in our control."
- Site claims full disk encryption, no user info collected, but explicitly states "Don't! Don't trust any service on the dark net!" and recommends PGP.
- Used in threats (e.g. 2024 bomb threat via dnmx.org variant) and flagged by security tools (Gridinsoft 1/100 trust score, medium risk on email validators).
- Domain change notice: .su not renewable due to "abuse"; emails forwarded until August 3, 2025; site promotes 310k+ active users and 2M+ monthly emails.
- No business registration details publicly available; operated anonymously with disclaimer against illegal use (terrorism, blackmail).
- Gridinsoftopen
"Gridinsoft blocks this website because it was classified as suspicious website. dnmx.cc should not be treated as a safe website. ... 1/100 trust score"
- Forbesopen
"cops believed DNMX was being used for the trade of child sex abuse material, terrorist communications and narcotics trafficking"
- LinkedInopen
"received an email from an account hosted on DNMX(.org) ... threatened mass bodily harm to students of this college via explosives and firearms"
Site explicitly announces migration from dnmx.su (previous domain seized by Dutch police in 2023) to dnmx.cc due to registrar abuse concerns; continues same anonymous darknet email service
Scam Network Intelligence
Antivirus Engines
Security Scans
Checked against the major public blocklists used by browsers and security tools — no hits.
Contact Verification
We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.
- No phone number listed on the page.
- No postal address visible on the page.
- Page impersonates Google on a non-official domain.
- Login form present on a page impersonating Google — credential-harvest pattern.
- Contact email on the site's own domain (support@dnmx.cc).
Domain & Encryption
Redirect Chain
- 1301http://dnmx.cc/
- 2200https://dnmx.cc/
Server Reputation
Scam-Type Likelihood
2 scam-type patterns detected
2 of 13 categories showed signals
We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.
- Login form combined with brand impersonation (credential-harvest pattern).
- Page impersonates Google in a login flow.
- AI analyst tagged this as phishing / data-harvesting.
- Page claims to be Google.
- AI analyst tagged this as a brand / clone-site impersonation.
- Clustered with known brand-impersonation infrastructure.
2 of 13 categories showed signals
We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.
- Login form combined with brand impersonation (credential-harvest pattern).
- Page impersonates Google in a login flow.
- AI analyst tagged this as phishing / data-harvesting.
- Page claims to be Google.
- AI analyst tagged this as a brand / clone-site impersonation.
- Clustered with known brand-impersonation infrastructure.
Phishing site — act fast
This page shows signs of attempting to steal credentials or impersonate a trusted brand.
- Do not interact with dnmx.cc
Do not enter credentials, deposit money, download files, or install browser extensions from this site.
- If you already typed your password — change it now
Change the password on the legitimate site and anywhere else you re-used it. Turn on two-factor authentication. Review recent account activity.
- OpenReport the phishing URL
APWG (Anti-Phishing Working Group) accepts phishing reports at reportphishing@apwg.org. Google Safe Browsing reports help protect other users.
- OpenGet help on the forum
MalwareTips members can help you assess damage and next steps.
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
Safety FAQ
Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.
- Our automated security review flags dnmx.cc as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
- No — dnmx.cc scored 1/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
- Yes. dnmx.cc presents a valid TLSv1.3 certificate issued by Let's Encrypt · YE2, expiring in 74 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
- dnmx.cc is 11 months old, registered on 7/15/2025 through Realtime Register B.V.. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
- 6 out of 92 antivirus engines in our malware network flagged dnmx.cc as malicious or suspicious (3 outright malicious). Even one detection is a meaningful signal.
- No. dnmx.cc is not currently listed on the major browser blocklist feeds that modern browsers use.
- dnmx.cc resolves to an IP operated by Panamaserver.com in PA (usage type: Data Center/Web Hosting/Transit). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
- This is a permanent record of the scan run on June 27, 2026. The verdict and evidence above reflect that scan and do not change on their own. If circumstances around dnmx.cc have changed, MalwareTips staff can run a fresh scan, which re-runs every check from scratch and publishes an updated report.
User reviews & comments(0)
Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.