Verdict
safeifm.com shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | Corporate website for SAFE, a facility-management and corporate services provider in India. Provides service descriptions, contact numbers, email, office address and a request-call-back contact form. Content aligns with B2B service model; no financial-investment, credential-harvesting, or impersonation signals apparent in the visible text. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 17 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 7.1 years oldRegistered history | Clear |
| Web archive | Archived since 2021Public history exists | Clear |
| Certificate | Encrypted connectionIssued by YR2 | Noted |
The page as captured
No screenshot is retained for this report.
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: 3 to 10 years (registration continuity).
- Public web-archive history exists since 2021.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Security Alert
Fortinet, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
SAFE is a corporate website presenting an Indian business offering facility management, real-estate acquisition support, engineering and maintenance, workplace health and safety, compliance, relocation, training, and related consulting services. Its apparent business model is B2B service contracting rather than financial investment or consumer commerce.
Scam/Impersonation Risk
The principal risk is not the visible business description: the homepage presents a conventional corporate-services model, contains service descriptions, and provides a standard contact form without a login or payment interface. However, this benign presentation is contradicted by confirmed external blacklist status and multiple malicious detections associated with the domain. The available evidence does not establish a specific impersonated brand or a visible phishing workflow, but the external threat evidence is sufficiently serious to treat credential submission, financial interaction, downloads, and other sensitive activity as unsafe. The site's claims that it is a “startup organisation,” a “leading corporate service,” and has a “proven track record” are not independently substantiated by the supplied evidence.
- The homepage describes facility-management and corporate services and contains one ordinary contact form; no login form, hidden sensitive form, wallet connection, or credential-harvesting mechanism was observed.
- External reputation assessment recorded 17 malicious and 4 suspicious detections among 26 evaluated detections, with a confirmed blacklist result.
- The site’s technical behavior showed two failed collection runs and two console errors, while no cloaking, clipboard manipulation, wallet-drainer behavior, or external password form was observed.
Regulatory Verification Notes
The site presents operational policies and service information, including an “Our Code of Conduct” page and a “SAFE QMS Policy,” but the supplied content does not provide a clearly identified legal entity, licensing authority, registration number, or independently verified regulatory status. This is a material verification gap for any business relationship, although it is not by itself evidence of fraud. Domain registration is through GoDaddy.com, LLC, with the registrant details maintained through a privacy service; that is an administrative limitation rather than a demonstrated identity contradiction. The site's real-world operator remains unverified, and the confirmed external blacklist signal materially outweighs the otherwise conventional corporate presentation.
- The About, policy, and service content identifies SAFE and its operating themes but does not state a license number, licensing authority, or independently verifiable corporate registration.
- The domain was registered on 2019-08-28 and is approximately 7.06 years old; the registrar is GoDaddy.com, LLC.
- The site is hosted on AS394695, PUBLIC-DOMAIN-REGISTRY - PDR, US.
- The transport certificate is DV-validated, issued by YR2, and valid until 2026-12-05.
What to Verify Next
Before any business engagement, an independent party should confirm the operator’s full legal name, registered address, and authority to contract through an official corporate registry and, where relevant, the applicable Indian licensing or procurement registry. Contact details should be validated through an independently sourced business record rather than relying solely on the website. Any proposed payment instructions, document downloads, account access, or requests for sensitive information should be confirmed through a separate, trusted communication channel.
- The website’s contact page provides telephone numbers, an office address, and a request-call-back form but does not independently establish the operator’s legal identity.
- The service and policy pages describe commercial offerings and internal policies without presenting a licensing authority or registration number.
- The homepage capture returned successfully with visible text and a standard contact form, providing material for offline comparison against independently sourced records.
Summary Verdict
The overall posture is critical and unsuitable for sensitive interaction. The site’s professional corporate presentation is materially outweighed by confirmed blacklist status and substantial malicious detections, while the operator’s real-world identity remains unverified. Informational viewing may be limited to non-sensitive purposes, but the evidence does not support treating the website as trustworthy for credentials, financial activity, or business-critical submissions.
Infrastructure Integrity
The domain resolves directly to one identified IP address, with no CDN or WAF edge layer observed and no separate origin-protection layer indicated. The hosting infrastructure is attributable to PUBLIC-DOMAIN-REGISTRY - PDR in India; this provides technical attribution but does not establish legitimacy. The DV TLS certificate protects transport confidentiality, yet certificate validity alone cannot offset the external threat findings.
Closing Assessment
The appropriate enterprise response is to suspend sensitive interaction and require independent identity, registry, and communication-channel validation before any engagement proceeds. Any already-submitted credentials or financial information should be handled under the organisation’s incident-response and account-protection procedures.
Written analysis generated 2026-09-17 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, external reputation.
01 Governance Risk
- Registration details are held behind a privacy service, so no operator is named publicly. This is common and legal, and it also means there is nobody to check.Registration and ownership
rule:KF_WHOIS_PRIVATE - The registration record withholds contact details for the operator.Registration and ownership
rule:KF_WHOIS_HIDDEN
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation
rule:EXT_BLACKLIST_CRITICAL
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 25% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of safeifm.com.
- The request stayed on safeifm.com. It was not redirected to another domain. Clear
- Registration is published under GoDaddy.com, LLC. Clear
- DNS for this domain is served by webhostbox.net, across 2 name servers. Noted
- The registration is paid up to 2027-08-28. Noted
- The earliest public archive of this site is from 2021-03-26. Clear
- It is hosted on PUBLIC-DOMAIN-REGISTRY, from a server in IN. Noted
Domain intelligence
| Registrar | GoDaddy.com, LLC |
|---|---|
| Hosting | PUBLIC-DOMAIN-REGISTRY - PDR, US |
| Country | IN |
| Server IP | 111.118.212.120 |
| Name servers | NS1.BH-IN-24.WEBHOSTBOX.NET, NS2.BH-IN-24.WEBHOSTBOX.NET |
| SSL issuer | YR2 |
| SSL expiry | 2026-12-05 |
| Domain age | 7.06 years (continuous registration) |
| Domain expiry | 2027-08-28 |
| Archive first seen | 2021-03-26 |
| Archive snapshots | Not counted (archive lookup incomplete) |
| Reputation | VirusTotal: 17 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about safeifm.com at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.