Is don.co.ke safe or a scam?

don.co.ke shows an 'Account Suspended' page on a 1.6-year-old domain with mixed antivirus signals and a 35/100 trust score from one independent scanner.

Medium Risk
Phishing / Credential Theft
Captured page preview of don.co.ke

At a glance

Antivirus · registration · identity
Antivirus detections
3 flagged
2 malicious · 1 suspicious
alphaMountain.ai
Domain registration
Dec 19, 2024Registered
1.6 years oldAt scan time
Operator identity
Claimed Only
Contact details are present but not independently verified
Verified factsSaved with this scan
  1. 2 engines classified the URL as malicious and 1 as suspicious; 58 returned harmless, 31 returned undetected, and 0 returned no usable result.
  2. gridinsoft.com: don.co.ke has a blacklist warning and a 35/100 trust score. Verify the site identity before use and avoid sending sensitive or payment data.
  3. The domain was registered Dec 19, 2024 and was 1.6 years old at scan time.
  4. Operator identity: Claimed Only. Contact details are present but not independently verified
  5. Google Safe Browsing returned no listed threat categories for this address at scan time.

Intelligence

The site presents itself as a suspended hosting account page rather than an active service. The visitor journey ends at a static suspension notice that includes language about account verification and suspension warnings, while the domain itself is only 1.6 years old and carries mixed security signals from antivirus engines and an independent scanner.

Evidence Map

Reputation
Concern

One or more reputation sources recorded a concern

Identity
Limited

Contact details are present but not independently verified

Behavior
Limited

Only partial behavior evidence was available

History
Observed

The domain was registered Dec 19, 2024 and was 1.6 years old at scan time.

Risk Factors
  • 1Two antivirus engines flagged the URL as malicious; one flagged it as suspicious
  • 2Independent scanner reports blacklist warning and 35/100 trust score
  • 3Page contains phishing language (account verification, suspension warnings)
  • 4No phone number or postal address listed on the page
Positive Signals
  • 1Valid TLSv1.3 certificate presented at scan time
  • 2Hosting IP abuse-confidence score 0/100 from three reports
  • 3Contact email uses the site's own domain (webmaster@don.co.ke)

Observed page content

The captured page shows the title 'Account Suspended' and the message 'This Account has been suspended. Contact your hosting provider for more information.' No login form, countdown timer, or deceptive notification bait was recorded.

Domain and registration details

The domain don.co.ke was registered on 19 December 2024 and is 1.6 years old at scan time. Registration privacy protection was not observed in the saved record. The registrar is listed as Kenya Network Information Centre in one cited source.

Security signals

Two antivirus engines classified the URL as malicious and one as suspicious. Google Safe Browsing returned no listed threat categories. The hosting IP carries an abuse-confidence score of 0/100 from three reports. The site presented a valid TLSv1.3 certificate.

Independent source rating

Gridinsoft reports a blacklist warning and a 35/100 trust score, stating the site is classified as suspicious based on multiple risk signals including three blacklist detections. The same source notes the hosting provider as Cloudflare, Inc., San Francisco, California, US.

Visitor journey and contact fields

The redirect path contained two hops with no cross-domain, homoglyph, or internationalized-domain indicators. The page lists one contact email on its own domain (webmaster@don.co.ke) and no phone number or postal address. Traffic presence was not indexed in the saved result.

Website Preview

Captured page preview of don.co.ke
Visual findings

Screenshot capture was incomplete; HTML content corroborates a functional site.

  1. 1Displays a generic 'Account Suspended' notification typical of hosting provider error pages
  2. 2Screenshot incomplete (slow render) — page HTML loaded normally, ignoring parked-domain heuristic.

Web Research

Gridinsoft lists don.co.ke with a blacklist warning and 35/100 trust score, classifying it as a suspicious website based on multiple risk signals including three blacklist detections. The source recommends verifying site identity before use and avoiding sending sensitive or payment data. Registrar is listed as Kenya Network Information Centre and hosting provider as Cloudflare, Inc., San Francisco, California, US.

gridinsoft.com

don.co.ke has a blacklist warning and a 35/100 trust score. Verify the site identity before use and avoid sending sensitive or payment data.

Single source
Source: gridinsoft.comView source
Don.co.ke Scam Check: Blacklist Warning (35/100 Trust Score)

Registrar listed as Kenya Network Information Centre

Single source
Source: Don.co.ke Scam Check: Blacklist Warning (35/100 Trust Score)View source
Don.co.ke Scam Check: Blacklist Warning (35/100 Trust Score)

Hosting provider: Cloudflare, Inc., San Francisco, California, US

Single source
Source: Don.co.ke Scam Check: Blacklist Warning (35/100 Trust Score)View source
Don.co.ke Scam Check: Blacklist Warning (35/100 Trust Score)

Suspicious Website This site is classified as Suspicious Website based on multiple risk signals, including 3 blacklist detections.

Single source
Source: gridinsoft.comView source
Don.co.ke Scam Check: Blacklist Warning (35/100 Trust Score)

Registrar: Kenya Network Information Centre

Single source
Source: gridinsoft.comView source
Don.co.ke Scam Check: Blacklist Warning (35/100 Trust Score)

Hosting Provider AS13335 Cloudflare, Inc. San Francisco, California, US

Single source
Source: gridinsoft.comView source

Threat Detection

Antivirus results, browser warnings, isolated page observations, and the threat pattern identified in this report.

Antivirus distribution
Recorded engine classifications, not a blanket clean bill
92 engines
Malicious2
Suspicious1
Harmless58
Undetected31
No result0
Antivirus consensus

Antivirus engine results

Result date Jul 21, 2026
Detection matrix
3 engines flagged this URL

This scan saved classifications from an antivirus network of 92 engines. Each malicious or suspicious classification is listed below by engine name and should be weighed with the rest of the report.

2Malicious1Suspicious58Harmless31Undetected0No result92Engines
0
of 92
alphaMountain.ai
Malicious· phishing
ChainPatrol
Malicious· malicious
Gridinsoft
Suspicious· suspicious

3 antivirus engines flagged this URL. A single classification is not consensus by itself. Review its label together with the page, identity, behavior, and history evidence shown in this report.

Threat pattern
Phishing / Credential Theft
Threat tags
parked domain
Top reasons

Evidence behind this threat profile

4 reasons
  1. 1Two antivirus engines flagged the URL as malicious; one flagged it as suspicious
  2. 2Independent scanner reports blacklist warning and 35/100 trust score
  3. 3Page contains phishing language (account verification, suspension warnings)
  4. 4No phone number or postal address listed on the page
Scam-Type Likelihood

2 of 22 categories showed signals

This profile separates the site's primary threat from other patterns supported by the saved page evidence, public research, and security findings.

Top match: Parked Domain
Parked Domain
High likelihood
80/100
  • Title and body text explicitly state 'Account Suspended' with instruction to contact hosting provider
  • Visual analysis confirms generic hosting error page rather than functional site content
  • No contact details, login forms, or commercial elements present
Phishing
Moderate likelihood
30/100
  • Two AV engines flagged the domain (alphaMountain.ai: phishing; ChainPatrol: malicious)
  • Gridinsoft report cites blacklist warning and 35/100 trust score
  • Page text contains generic suspension language that could be repurposed for phishing lures
Related site context

Related scanned sites

Shared visual or page pattern
evident-lavender-mvnhhiof.edgeone.devnationalacademies.orgseaglobalfx.comspectrademarket.comtrezarsuit-en.wasmer.appvertexvaults.com

Technical Details

Identity, domain, infrastructure, and connection facts saved with this scan.

July 21, 2026 at 12:31 PM UTC

Identity

6 facts
Operator
Claimed Only
On-domain email
1 address
Other email
Not observed
Phone
Not observed
Postal address
Not observed
Social profiles
Not observed

Domain

8 facts
Domain age
1.6 years old
Registered
Dec 19, 2024
Registrar
Unavailable
Expires
Dec 19, 2026
WHOIS updated
Feb 14, 2026
Registrant
Unavailable
Registration country
Unavailable
WHOIS privacy
Not observed

Infrastructure

14 facts
HTTPS
Valid certificate
TLS protocol
TLSv1.3
Certificate issuer
Google Trust Services · WE1
Certificate subject
don.co.ke
Certificate valid from
Jun 12, 2026
Certificate valid to
Sep 10, 2026
Network address
104.21.49.21
ASN
Unavailable
Hosting organization
Cloudflare, Inc.
Country
US
Server
cloudflare
Site platform
Unavailable
IP reputation
0% confidence · 3 reports
Tor exit node
No

Connections

13 facts
Scan scope
Domain
Destination host
don.co.ke
Redirects
2
Cross-domain redirect
No
Redirect status codes
301 → 302 → 200
Lookalike characters
Not observed
Internationalized domain
No
Page response
200
Observation coverage
Unavailable
Extracted links
Unavailable
Unique IPs contacted
Unavailable
Countries contacted
Unavailable
Referenced domains
2

What to do

1
Before interacting
Use normal caution

Use normal caution. Verify the site identity before use and avoid sending sensitive or payment data.

2
If you already interacted

If you entered a password, change it on the official service by typing its known address yourself, enable two-factor authentication, and review recent account activity. Contact your bank if you also entered payment details.

Final Verdict

Use normal caution

Why this verdict

The verdict is suspicious because the domain is 1.6 years old, two antivirus engines flagged the URL as malicious, one independent source lists a blacklist warning and 35/100 trust score, and the page displays a generic 'Account Suspended' notice with phishing-language concerns.

Recommendation

Use normal caution. Verify the site identity before use and avoid sending sensitive or payment data.

Key evidence

  1. 1Two antivirus engines flagged the URL as malicious; one flagged it as suspicious
  2. 2Independent scanner reports blacklist warning and 35/100 trust score
  3. 3Page contains phishing language (account verification, suspension warnings)
Evidence: strongScope: DomainFresh scan: July 21, 2026 at 12:31 PM UTC

Safety FAQ

Is don.co.ke safe to use?+

The verdict is suspicious because the domain is 1.6 years old, two antivirus engines flagged the URL as malicious, one independent source lists a blacklist warning and 35/100 trust score, and the page displays a generic 'Account Suspended' notice with phishing-language concerns.

What should I do about don.co.ke?+

Use normal caution. Verify the site identity before use and avoid sending sensitive or payment data.

How old is don.co.ke?+

don.co.ke is 1.6 years old and was registered dec 19, 2024.

What if I already interacted with don.co.ke?+

If you entered a password, change it on the official service by typing its known address yourself, enable two-factor authentication, and review recent account activity. Contact your bank if you also entered payment details.

When was this report updated?+

This report reflects the scan completed July 21, 2026 at 12:31 PM UTC.