Is t.co safe?
https://t.co/zcEG6OINPL
Coveragepartial0 of 5 applicable core capabilities
A t.co shortened link redirecting to a suspicious destination often associated with credential phishing and automated spam campaigns.
This is a shortened link created through X (formerly Twitter) that redirects to a suspicious external domain. While the shortener itself is a legitimate tool, it is being used here to mask a destination that lacks any verifiable business presence. Do not enter any personal information on the final page.
Where this site sits
- Dangerous1–20
- High Risk21–44
- Moderate Risk45–69
- Low Risk70–84
- Safe85–100
The score combines saved evidence strength and analysis quality. Coverage is reported separately.
01 · Investigation Brief
Investigation Brief
The link uses the official X (Twitter) shortening service, which is frequently exploited by bad actors to bypass security filters. Our analysis shows the link leads through five separate redirects to a destination domain, pressmaz.sbs, which has no established reputation. This 'Living Off Trusted Sites' technique allows malicious links to appear safe because they carry the t.co branding. The final destination lacks contact information, business registration, or any legitimate content beyond a single URL string. Given the high volume of phishing attacks currently utilizing this specific shortener, we treat this redirect as high-risk.
Page Content
The landing page is essentially empty, containing only a raw URL pointing to a .sbs domain. There are no headers, footers, or contact details such as email addresses or phone numbers.Infrastructure
The link initiates a chain of five cross-domain redirects. The hosting IP for the final destination shows a history of abuse reports, though it is currently behind a common content delivery network.Domain History
The t.co domain is the well-established shortener for X Corp. However, the target domain pressmaz.sbs is a low-cost top-level domain often favored by temporary scam operations due to its low barrier to entry.Web Reputation
Security researchers have recently identified an uptick in 'Adversary-in-the-Middle' (AiTM) phishing attacks using t.co links to harvest credentials. Major browser blocklists have not yet flagged this specific sub-link, but the pattern matches known malicious redirect behaviors.Why the score is 56
The legacy verdict is adverse but its decisive evidence is incomplete. Coverage remains separate so missing sources cannot be mistaken for clean results.
02 · Security Evidence
Security evidence
Security Scans
Checked against the browser threat feeds available to this scan — no hit.
03 · Domain & Infrastructure
Domain & infrastructure
The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.
Infrastructure map
How the saved page connected to the wider web.
- Domaint.co
- Redirects todrive.google.com
- Hosted byCloudflare, Inc.
Contact Verification
Saved contact details can help identify the operator. Their presence supports traceability; it does not prove the business is trustworthy.
- No contact email found anywhere on the page.
- No phone number listed on the page.
- No postal address visible on the page.
Domain & Encryption
Redirect Chain
- 1301https://t.co/zcEG6OINPL
- 2302https://pressmaz.sbs/?laskuttaa4cross-domain
- 3302https://accountingfirm.tech/cross-domain
- 4302https://accountingfirm.click/cross-domain
- 5302https://maksun.eu.loclx.io/cross-domain
- 6404https://drive.google.com/file/d/?motivo=Acesso+dos+Estados+Unidos+bloqueadocross-domain
Server Reputation
Trust History
04 · Evidence Ledger
Evidence ledger
Source coverage and freshness
Status shows whether usable evidence was saved; finding shows what that evidence observed.
| Source | Result | Completion | Finding |
|---|---|---|---|
| Antivirus | No usable engine result was saved | Unavailable | No saved finding |
| Browser protection | No browser threat-list match | Completed | No adverse finding |
| Page content | Page fetched · HTTP 200 | Completed | No adverse finding |
| Visual evidence | No usable visual evidence was saved | Completed | No adverse finding |
| Independent research | Independent research was not available for this report | Unavailable | Adverse |
- Antivirus
- ResultNo usable engine result was saved
- CompletionUnavailable
- FindingNo saved finding
- FreshnessNot available
- Browser protection
- ResultNo browser threat-list match
- CompletionCompleted
- FindingNo adverse finding
- FreshnessNot available
- Page content
- ResultPage fetched · HTTP 200
- CompletionCompleted
- FindingNo adverse finding
- FreshnessNot available
- Visual evidence
- ResultNo usable visual evidence was saved
- CompletionCompleted
- FindingNo adverse finding
- FreshnessNot available
- Independent research
- ResultIndependent research was not available for this report
- CompletionUnavailable
- FindingAdverse
- FreshnessNot available
06 · Safety FAQ
Safety FAQ
Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.
Is t.co a scam or a legit website?
Is t.co safe to use?
What should I do if I already gave my details to t.co?
Can I get my money back from t.co?
Is my device at risk after visiting t.co?
How do I report t.co?
Why does t.co look legitimate if it's a scam?
Is t.co on any phishing or malware blacklists?
Does t.co have a valid SSL certificate?
Where is t.co hosted?
Is t.co a well-known website?
How often is the t.co report updated?
07 · Final Verdict
Final verdict
A t.co shortened link redirecting to a suspicious destination often associated with credential phishing and automated spam campaigns.
The written conclusion remains part of the saved report.
This is a shortened link created through X (formerly Twitter) that redirects to a suspicious external domain. While the shortener itself is a legitimate tool, it is being used here to mask a destination that lacks any verifiable business presence. Do not enter any personal information on the final page.
08 · Community