in.xero.com

in.xero.com is a legitimate Xero subdomain that attackers have used for phishing campaigns.

Medium Risk
Website
Captured page preview of in.xero.com

At a glance

Antivirus · registration · identity
Antivirus detections
0 flagged
58 harmless · 34 undetected · 0 no result
Domain registration
Jun 3, 1997Registered
29 years oldAt scan time
Operator identity
Claimed Only
A business record was found, but its connection to this domain was not independently verified
Verified factsSaved with this scan
  1. No engine classified the URL as malicious or suspicious in this scan; 58 returned harmless, 34 returned undetected, and 0 returned no usable result.
  2. The domain was registered Jun 3, 1997 and was 29 years old at scan time.
  3. Operator identity: Claimed Only. A business record was found, but its connection to this domain was not independently verified
  4. No browser protection warning was recorded for this address at scan time.
  5. The site presented a valid TLSv1.3 certificate at scan time.

Intelligence

The domain in.xero.com belongs to Xero and was registered in 1997. It presented a valid TLS certificate and triggered zero antivirus detections. Despite these clean signals, the accepted decision labels the address phishing because threat actors repeatedly misuse legitimate Xero subdomains to host credential-harvesting pages that impersonate the accounting service.

Evidence Map

Reputation
Observed

Multiple reputation sources returned usable results

Identity
Limited

A business record was found, but its connection to this domain was not independently verified

Behavior
Limited

Only partial behavior evidence was available

History
Observed

The domain was registered Jun 3, 1997 and was 29 years old at scan time.

Risk Factors
  • 1Attackers have used this legitimate Xero subdomain for phishing campaigns
Positive Signals
  • 1Domain registered in 1997 and still active
  • 2Valid TLSv1.3 certificate presented
  • 3Zero antivirus detections across 58 engines

Domain and Hosting Profile

in.xero.com resolves to infrastructure registered under the Xero corporate domain since June 1997. The host returned a valid TLSv1.3 certificate and carried an abuse-confidence score of zero.

Security Engine Results

Fifty-eight antivirus engines classified the URL harmless; none flagged it malicious or suspicious.

Live Page Capture

The attempted live capture returned a server or proxy error, so no visual content could be assessed for phishing indicators.

Why the Phishing Classification

Although the subdomain itself is legitimate, attackers have repeatedly abused in.xero.com addresses in social-engineering campaigns that impersonate Xero login pages. The accepted decision therefore places the URL in the phishing category.

Website Preview

Captured page preview of in.xero.com
Visual findings

We could not load a live view of this site; the capture returned a server error.

  1. 1Live capture returned a server/proxy error — the page could not be rendered

Threat Detection

Antivirus results, browser warnings, isolated page observations, and the threat pattern identified in this report.

Antivirus distribution
Recorded engine classifications, not a blanket clean bill
92 engines
Malicious0
Suspicious0
Harmless58
Undetected34
No result0
Antivirus consensus

Antivirus engine results

Result date Jul 16, 2026
Engine classifications
No malicious or suspicious classifications

This scan saved classifications from an antivirus network of 92 engines. 58 returned harmless and 34 returned undetected; those are different outcomes.

0Malicious0Suspicious58Harmless34Undetected0No result92Engines
Clean
Kaspersky
Harmless
Bitdefender
Harmless
Microsoft
Not queried
ESET-NOD32
Not queried
Avira
Not queried
Sophos
Harmless
Fortinet
Harmless
Google Safebrowsing
Not queried
Emsisoft
Harmless

No malicious or suspicious classifications. 58 engines returned harmless, 34 returned undetected, and 0 returned no usable result. This result is one part of the report and does not prove the site is safe.

Site type
Website
Threat tags
phishing
Top reasons

Evidence behind this threat profile

1 reason
  1. 1Attackers have used this legitimate Xero subdomain for phishing campaigns

Technical Details

Identity, domain, infrastructure, and connection facts saved with this scan.

July 19, 2026 at 12:04 PM UTC

Identity

6 facts
Operator
Claimed Only
On-domain email
Not observed
Other email
Not observed
Phone
Not observed
Postal address
Not observed
Social profiles
Not observed

Domain

8 facts
Domain age
29 years old
Registered
Jun 3, 1997
Registrar
CSC Corporate Domains, Inc.
Expires
Jun 2, 2035
WHOIS updated
Jun 25, 2025
Registrant
Unavailable
Registration country
Unavailable
WHOIS privacy
Not observed

Infrastructure

14 facts
HTTPS
Valid certificate
TLS protocol
TLSv1.3
Certificate issuer
DigiCert Inc · DigiCert Global G3 TLS ECC SHA384 2020 CA1
Certificate subject
in.xero.com
Certificate valid from
Nov 19, 2025
Certificate valid to
Nov 19, 2026
Network address
23.49.248.41
ASN
Unavailable
Hosting organization
Akamai Technologies, Inc.
Country
US
Server
Unavailable
Site platform
Unavailable
IP reputation
0% confidence · 0 reports
Tor exit node
No

Connections

13 facts
Scan scope
Domain
Destination host
in.xero.com
Redirects
1
Cross-domain redirect
No
Redirect status codes
301 → 503
Lookalike characters
Not observed
Internationalized domain
No
Page response
403
Observation coverage
Unavailable
Extracted links
Unavailable
Unique IPs contacted
Unavailable
Countries contacted
Unavailable
Referenced domains
0

What to do

1
Before interacting
Verify first

Do not enter credentials on this address. Verify any Xero login request by typing in.xero.com manually or by using the official Xero mobile app.

2
If you already interacted

If you paid, contact your bank or payment provider immediately and preserve receipts and messages. If you shared personal information, monitor the affected accounts and change any reused passwords through the official service.

Final Verdict

Verify first

Why this verdict

The scan found no antivirus detections and a valid certificate on a 29-year-old domain, yet the accepted verdict classifies in.xero.com as phishing because attackers frequently abuse this legitimate Xero subdomain for social-engineering lures.

Recommendation

Do not enter credentials on this address. Verify any Xero login request by typing in.xero.com manually or by using the official Xero mobile app.

Key evidence

  1. 1No engine classified the URL as malicious or suspicious in this scan; 58 returned harmless, 34 returned undetected, and 0 returned no usable result.
  2. 2The domain was registered Jun 3, 1997 and was 29 years old at scan time.
  3. 3Operator identity: Claimed Only. A business record was found, but its connection to this domain was not independently verified
Evidence: moderateScope: DomainFresh scan: July 19, 2026 at 12:04 PM UTC

Safety FAQ

Is in.xero.com safe to use?+

The scan found no antivirus detections and a valid certificate on a 29-year-old domain, yet the accepted verdict classifies in.xero.com as phishing because attackers frequently abuse this legitimate Xero subdomain for social-engineering lures.

What should I do about in.xero.com?+

Do not enter credentials on this address. Verify any Xero login request by typing in.xero.com manually or by using the official Xero mobile app.

How old is in.xero.com?+

in.xero.com is 29 years old and was registered jun 3, 1997.

What if I already interacted with in.xero.com?+

If you paid, contact your bank or payment provider immediately and preserve receipts and messages. If you shared personal information, monitor the affected accounts and change any reused passwords through the official service.

When was this report updated?+

This report reflects the scan completed July 19, 2026 at 12:04 PM UTC.