Is dop-test.network safe?
http://dop-test.network/
Coveragestrong0 of 5 applicable core capabilities
Unofficial DOP Protocol clone using a credential-harvesting pattern to collect email and MetaMask wallet connections on a non-standard domain.
This site is an unofficial clone of the Data Ownership Protocol (DOP) testnet that uses a credential-harvesting pattern to collect email addresses and wallet connections. The official project operates on a different domain, making this a high-risk impersonation.
Where this site sits
- Dangerous1–20
- High Risk21–44
- Moderate Risk45–69
- Low Risk70–84
- Safe85–100
The score combines saved evidence strength and analysis quality. Coverage is reported separately.
01 · Investigation Brief
Investigation Brief
The site imitates the official Data Ownership Protocol (DOP) testnet but resides on a domain unrelated to the project's verified web presence. Our analysis identified a credential-harvesting pattern where the page prompts for an email address and a MetaMask connection, which is a common tactic for capturing user data or initiating unauthorized wallet interactions. While the official testnet is hosted at doptest.dop.org, this site uses a standalone domain registered recently. The lack of any verifiable business contact information or official links further indicates this is an unauthorized mirror. We have flagged this as suspicious due to the high risk of phishing and the direct impersonation of a known crypto project.
Page Content
The storefront presents a minimalist 'Testnet' entry portal for the Data Ownership Protocol. It specifically instructs users to use the Chrome browser with the MetaMask extension and requires an email address to proceed.Infrastructure
The site is hosted behind a common content delivery network and uses a valid SSL certificate. However, it lacks any public WHOIS data or corporate registration details, which is atypical for a legitimate financial or protocol-based project.Domain History
The domain is relatively new and does not appear in global traffic rankings. It is not the official domain used by the DOP project for its public testnet operations.Web Reputation
While some automated scanners haven't yet blacklisted the URL, our internal fingerprinting confirms it is a clone of the official dop.org site. There is a notable absence of legitimate business documentation or social media links.Why the score is 45
The legacy verdict is adverse but its decisive evidence is incomplete. Coverage remains separate so missing sources cannot be mistaken for clean results.
02 · Security Evidence
Security evidence
Antivirus Engines
0/ 92
No detectionsSaved result
No detections across 92 engines
No antivirus engine in this saved scan raised an adverse result. This is one signal, not a guarantee.
- Malicious
- 0
- Suspicious
- 0
- Total
- 92
All 92 engine results
- 0xSI_f33d - unrated - Clean
- Abusix - clean - Clean
- Acronis - clean - Clean
- ADMINUSLabs - clean - Clean
- AILabs (MONITORAPP) - clean - Clean
- AlienVault - clean - Clean
- alphaMountain.ai - unrated - Clean
- AlphaSOC - unrated - Clean
- Antiy-AVL - clean - Clean
- ArcSight Threat Intelligence - unrated - Clean
- AutoShun - unrated - Clean
- Bfore.Ai PreCrime - unrated - Clean
- BitDefender - clean - Clean
- Bkav - unrated - Clean
- BlockList - clean - Clean
- Blueliv - clean - Clean
- Certego - clean - Clean
- ChainPatrol - unrated - Clean
- Chong Lua Dao - unrated - Clean
- CINS Army - clean - Clean
- Cluster25 - unrated - Clean
- CRDF - clean - Clean
- Criminal IP - unrated - Clean
- CSIS Security Group - unrated - Clean
- CTX AI - clean - Clean
- Cyan - unrated - Clean
- Cyble - clean - Clean
- CyRadar - clean - Clean
- desenmascara.me - clean - Clean
- DNS8 - unrated - Clean
- Dr.Web - clean - Clean
- EmergingThreats - clean - Clean
- Emsisoft - clean - Clean
- Ermes - unrated - Clean
- ESET - clean - Clean
- ESTsecurity - clean - Clean
- Forcepoint ThreatSeeker - clean - Clean
- Fortinet - clean - Clean
- G-Data - clean - Clean
- GCP Abuse Intelligence - unrated - Clean
- Google Safebrowsing - clean - Clean
- GreenSnow - clean - Clean
- GreyNoise - unrated - Clean
- Gridinsoft - unrated - Clean
- Guardpot - unrated - Clean
- Heimdal Security - clean - Clean
- Hunt.io Intelligence - unrated - Clean
- IPsum - clean - Clean
- Juniper Networks - clean - Clean
- K7AntiVirus - unrated - Clean
- Kaspersky - unrated - Clean
- LevelBlue - clean - Clean
- Lionic - clean - Clean
- Lumu - unrated - Clean
- Malwared - clean - Clean
- MalwarePatrol - clean - Clean
- MalwareURL - unrated - Clean
- Mimecast - unrated - Clean
- Netcraft - unrated - Clean
- OpenPhish - clean - Clean
- PhishFort - unrated - Clean
- Phishing Database - clean - Clean
- PhishLabs - unrated - Clean
- Phishtank - clean - Clean
- PREBYTES - clean - Clean
- PrecisionSec - unrated - Clean
- Quick Heal - clean - Clean
- Quttera - clean - Clean
- Rising - clean - Clean
- SafeToOpen - unrated - Clean
- Sangfor - clean - Clean
- Sansec eComscan - unrated - Clean
- Scantitan - clean - Clean
- SCUMWARE.org - clean - Clean
- Seclookup - clean - Clean
- Snort IP sample list - unrated - Clean
- SOCRadar - unrated - Clean
- Sophos - clean - Clean
- StopForumSpam - clean - Clean
- Sucuri SiteCheck - clean - Clean
- ThreatHive - clean - Clean
- URLhaus - clean - Clean
- URLQuery - unrated - Clean
- Viettel Threat Intelligence - clean - Clean
- VIPRE - unrated - Clean
- ViriBack - clean - Clean
- VX Vault - clean - Clean
- Webroot - clean - Clean
- Xcitium Verdict Cloud - clean - Clean
- Yandex Safebrowsing - clean - Clean
- ZeroCERT - clean - Clean
- ZeroFox - unrated - Clean
Security Scans
Checked against the browser threat feeds available to this scan — no hit.
What we observed
Visual warning signs were identified
The page appears to be a legitimate entry portal for a cryptocurrency testnet environment, showing no immediate visual indicators of a scam or phishing clone.
What the captured page showed
4 observations- 01
Page prompts for an email address to participate in a 'Testnet'
- 02
Specific recommendation to use Chrome with MetaMask extension
- 03
Minimalist design with a single functional form and terms agreement
- 04
Branding for 'DOP' (Data Ownership Protocol) is visible in the header
Brand impersonation signal
medium confidenceThe saved page presents itself in connection with MetaMask on a domain outside that brand's official property. A login form was also observed, which materially increases the risk.
03 · Investigation Story
Investigation story
What the site claims
DOP my
What we observed
The page content was captured and checked alongside 92 antivirus results.
What independent research found
No complete independent-research result was available in this saved report.
What remains unverified
5 of the 5 applicable core capabilities did not complete, so those gaps remain visible in the coverage ledger.
If this is a scam — what it means for you
You were probably about to log in or type personal details here.
If it is, anything you enter — username, password, card number, one-time code — goes straight to criminals, who use it to take over your real accounts and drain them.
If this is a scam, how it works
The typical trap, step by step
This site is unverified — it may be legitimate. If it is a scam, this is the playbook pages like it follow:
They clone a real login page (a bank, email provider, PayPal, a courier) pixel-for-pixel.
You're driven here by an email, text, or ad with an urgent reason to “verify”, “unlock”, or “confirm” your account.
You type your username and password — which flow straight to the scammers instead of the real company.
They log into your real account, change the password, and drain it or sell the access.
Do not enter your email address or connect your MetaMask wallet to this site. If you wish to participate in the DOP testnet, only use the official link provided by the project's verified social media or their main website at dop.org.
Risk pattern correlation
Scam-Type Likelihood
3 of 21 categories showed signals
Each card names a specific harm pattern and the concrete facts that support it. The category score is supporting context; the report verdict above remains the final severity decision.
- Login form combined with brand impersonation (credential-harvest pattern).
- Page impersonates MetaMask in a login flow.
- The evidence pattern matches phishing / data-harvesting.
- Page claims to be MetaMask.
- The evidence pattern matches crypto fraud / wallet-drainer activity.
- The captured site is crypto-themed; that alone does not prove fraud.
18Show remaining categoriesHide checked categories
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
04 · Domain & Infrastructure
Domain & infrastructure
The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.
Infrastructure map
How the saved page connected to the wider web.
- Domaindop-test.network
- Redirects todop-test.network
- Hosted byCloudflare, Inc.
- Referencesdoptest.dop.org · fonts.googleapis.com
Contact Verification
Saved contact details can help identify the operator. Their presence supports traceability; it does not prove the business is trustworthy.
- No contact email found anywhere on the page.
- No phone number listed on the page.
- No postal address visible on the page.
- Page impersonates MetaMask on a non-official domain.
- Login form present on a page impersonating MetaMask — credential-harvest pattern.
Domain & Encryption
Server Reputation
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
05 · Evidence Ledger
Evidence ledger
Source coverage and freshness
Status shows whether usable evidence was saved; finding shows what that evidence observed.
| Source | Result | Completion | Finding |
|---|---|---|---|
| Antivirus | 0 of 92 engines flagged | Completed | No adverse finding |
| Browser protection | No browser threat-list match | Completed | No adverse finding |
| Page content | Observed page mechanics raised a material concern | Completed | Adverse |
| Visual evidence | 4 visible observations saved with the page capture | Limited | No saved finding |
| Independent research | Independent research was not available for this report | Unavailable | No saved finding |
- Antivirus
- Result0 of 92 engines flagged
- CompletionCompleted
- FindingNo adverse finding
- FreshnessNot available
- Browser protection
- ResultNo browser threat-list match
- CompletionCompleted
- FindingNo adverse finding
- FreshnessNot available
- Page content
- ResultObserved page mechanics raised a material concern
- CompletionCompleted
- FindingAdverse
- FreshnessNot available
- Visual evidence
- Result4 visible observations saved with the page capture
- CompletionLimited
- FindingNo saved finding
- FreshnessNot available
- Independent research
- ResultIndependent research was not available for this report
- CompletionUnavailable
- FindingNo saved finding
- FreshnessNot available
07 · Safety FAQ
Safety FAQ
Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.
Is dop-test.network a scam or a legit website?
Is dop-test.network safe to use?
What should I do if I already gave my details to dop-test.network?
Can I get my money back from dop-test.network?
Did dop-test.network steal my password or personal information?
How do I report dop-test.network?
Why does dop-test.network look legitimate if it's a scam?
Has dop-test.network been flagged by antivirus engines?
Is dop-test.network on any phishing or malware blacklists?
Does dop-test.network have a valid SSL certificate?
Where is dop-test.network hosted?
How often is the dop-test.network report updated?
08 · Final Verdict
Final verdict
Unofficial DOP Protocol clone using a credential-harvesting pattern to collect email and MetaMask wallet connections on a non-standard domain.
The written conclusion remains part of the saved report.
This site is an unofficial clone of the Data Ownership Protocol (DOP) testnet that uses a credential-harvesting pattern to collect email addresses and wallet connections. The official project operates on a different domain, making this a high-risk impersonation.
09 · Community