Verdict
payload.de appears legitimate.
Our checks found nothing pointing to fraud. Ordinary care still applies when you pay or sign in.
| What this site appears to be | A JavaScript-powered dashboard that visualizes pending Ethereum transactions, base and priority fees, and builder/validator metrics. The page content is descriptive and analytical with color-coded transaction categories and charts. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | None flagged itVirusTotal | Clear |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0% confidenceAbuseIPDB, 67 reports; shared hosting inflates reports | Clear |
| Domain age | 4.7 years oldRegistered history | Clear |
| Web archive | Archived since 202184 snapshots | Clear |
| Certificate | Encrypted connectionIssued by WR3 | Noted |
The page as captured
No screenshot is retained for this report.
Key findings
- Automated classification: Not Scam.
- Domain age: 3 to 10 years (registration continuity).
- Public web-archive history exists since 2021.
- VirusTotal and Google Safe Browsing had no flags for this domain; its hosting IP carries AbuseIPDB reports below the confidence level TrustSniffer treats as a flag.
Full analysis
Overview
The website is a JavaScript-powered Ethereum analytics dashboard that presents real-time visualizations of pending transactions, base and priority fees, builder bids, validator activity, and block-value metrics. Its apparent purpose is informational: it provides market and network telemetry without a visible deposit flow, monetization mechanism, credential request, or wallet-connection function in the captured experience.
Scam/Impersonation Risk
No blacklist, phishing, malware, brand-impersonation, or conflicting-identity contradictions were observed. The homepage describes a specific analytical function, uses transparent transaction-category explanations, and contains no login form, sensitive form, wallet-connect flow, external submission, or apparent fund-transfer mechanism. A separate infrastructure-reputation signal consists of abuse reports associated with a shared CDN address; that signal is discounted because the address is whitelisted, attributed to shared provider infrastructure, and carries zero confidence for the site itself. The available evidence is therefore consistent with an established, apparently legitimate informational website, although its real-world operator identity is not independently verified.
- The homepage presents Ethereum transaction-pool, fee, builder-bid, and block-value charts and contains no visible credential, payment, or wallet-request form.
- The captured site behavior recorded zero external XMLHttpRequests, zero wallet-connect runs, zero wallet-provider detections, zero hidden forms, and zero clipboard-write events across two successful runs.
- Domain registration continuity indicates a domain age of 4.6680355920602326 years.
- The site has 84 archive snapshots spanning 2021-12-10 to 2026-02-17, with 6 years tracked.
Regulatory Verification Notes
The displayed service appears to be an analytical software tool rather than a broker, exchange, deposit-taking service, or investment product, so no licensing claim is apparent from the captured homepage. The site does not independently establish the legal identity of its operator in the supplied evidence; this is an identity-verification limitation rather than an observed identity contradiction. Its broader reputation evidence is clean, and its established traffic footprint and sustained historical presence support an evidence-consistent legitimacy assessment. A mid-level page-authority signal is contextual only and does not independently establish legal status.
- The homepage describes a real-time informational dashboard and shows no visible monetization, deposit, trading-account, or investment-offer flow.
- The homepage has no visible legal, licensing, or corporate disclosure establishing the operator’s real-world identity.
- Hosted on AS54113 (FASTLY - Fastly, Inc., US).
- TLS certificate issued by WR3 at DV validation level, valid to 2026-10-17T21:54:07+00:00.
What to Verify Next
Before any future expansion into account, subscription, payment, or other sensitive functionality, independently confirm the operating entity through an official corporate or regulatory source, review applicable terms and privacy disclosures, and confirm payment protections and cancellation or refund provisions through an independent route. Any claimed regulated service should be checked against the relevant jurisdiction’s official registry rather than relying solely on statements made on the website. Contact channels should also be confirmed through an independently sourced official route.
- The captured homepage is an analytical dashboard with no account, payment, or deposit workflow to validate.
- The supplied evidence does not independently connect the website to a named real-world operator.
- The site’s visible business model is informational software, with no license authority or license number presented in the captured content.
Summary Verdict
The site presents a high-trust, low-risk posture based on converging technical, historical, behavioral, and reputation signals. It appears consistent with an established legitimate analytics service, while the absence of independent operator verification means that legitimacy should be described as apparent rather than proven.
Infrastructure Integrity
The website is protected by Fastly CDN/WAF infrastructure, with the observed address operating as a CDN edge on AS54113; the origin server was not observable in the analysis. This provides a meaningful mitigation against direct origin exposure and common delivery-layer abuse, but infrastructure protection alone is not proof of operator legitimacy.
Closing Assessment
Ordinary informational use is proportionate to the evidence; any later credential or payment interaction should first undergo routine independent checks of the operator, applicable terms, and payment protections.
Written analysis generated 2026-08-11 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
No rule findings contributed to this verdict.
Signals weighed against the site
- AbuseIPDB: 67 reports on hosting IP 199.36.158.100 (Google LLC, Content Delivery Network), 0% confidence. The reports are attributed to shared infrastructure, not specifically to this website.
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of payload.de.
- The request stayed on payload.de. It was not redirected to another domain. Clear
- DNS for this domain is served by registrar-servers.com, across 2 name servers. Noted
- The earliest public archive of this site is from 2021-12-10. Clear
- It is hosted on FASTLY, from a server in US. Noted
Domain intelligence
| Registrar | Not available |
|---|---|
| Hosting | FASTLY - Fastly, Inc., US |
| Country | US |
| Server IP | 199.36.158.100 |
| Name servers | dns1.registrar-servers.com, dns2.registrar-servers.com |
| SSL issuer | WR3 |
| SSL expiry | 2026-10-17 |
| Domain age | 4.67 years (continuous registration) |
| Domain expiry | Not available |
| Archive first seen | 2021-12-10 |
| Archive snapshots | 84 |
| Reputation | VirusTotal: 0 flagged | AbuseIPDB: 0% confidence, 67 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about payload.de at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.