Post

Replies

Boosts

Views

Activity

Reply to Possible increase in false positive “Fraudulent Website Warning” detections in Safari (2026)
I have a theory, and given the current situation it looks quite realistic. I checked the DNS: skvoz.net → 89.169.35.79 (AS210644) skvoz.org → 91.184.241.229 (AS210644) lastfix.app → 5.182.87.37 (AS210644) lastfix.video → 5.182.87.37 (AS210644) AS210644 = AEZA-AS, AEZA GROUP LLC, RU We are both hosted on Aeza, and it turns out that since 2025 Aeza has been under sanctions: https://www.chainalysis.com/blog/ofac-sanctions-aeza-group-bulletproof-hosting-crypto-payments-july-2025/ I'm afraid that in this case support won't even do anything, since they are not allowed to work with companies on the sanctions list. The only option I see is to move to a different, "clean" provider and get new domains. And in parallel, keep trying to reach support to get the domains removed from those lists. This looks extremely sketchy and ugly from every angle, because I only just found out that our hosting provider is a bulletproof hosting operation and, on top of that, is under sanctions. And what's being blocked isn't the provider itself - it's our new domains. I don't think this is a coincidence - most likely this is exactly the cause.
Topic: Safari & Web SubTopic: General Tags:
3h
Reply to Possible increase in false positive “Fraudulent Website Warning” detections in Safari (2026)
Same problem here, with two domains. Timeline lastfix.app went live around July 12, 2026. Safari began showing the “Deceptive Website” warning shortly after. I moved the product to a new domain, lastfix.video, on July 24. It was flagged as well. A detail that may be relevant to others here: the verdict appears to follow redirects. During the migration I left a 301 from lastfix.app to lastfix.video. The new domain picked up the warning almost immediately, despite having no history of its own — it had existed for hours. I have since replaced the redirect with a static page containing an ordinary link instead. If anyone else in this thread migrated domains with a redirect in place, that may explain why their second domain was flagged too. Same verification results as yours Google Search Console: no security issues on either domain. Google Safe Browsing Transparency Report: no unsafe findings for either domain. Chrome opens both domains without any warning. Only Safari warns. Valid Let’s Encrypt certificates on both, correct chains. Regarding your first question — yes, Apple maintains an independent list. Safari stores the Safe Browsing data it downloads under two separate provider directories, one for Google and one for Apple, each containing its own threat lists. The Apple directory has its own social_engineering list, distinct from Google’s. So a domain can be listed by Apple while every Google list is clean. That is precisely what “Google reports safe, Safari warns” looks like from the outside, and it means checking Google Safe Browsing tells you nothing about the Apple verdict. Same pattern you describe Both of my domains were newly registered. Both were flagged within roughly one to two weeks of going live. Nothing about the content changed between the clean period and the warning appearing. Not all users see the warning — roughly half of the people I asked do, on different networks and devices. That is consistent with the list propagating to devices gradually rather than a per-device or per-network cause. I am preparing a Website Review submission now. Has anyone here had one actually resolved, and roughly how long did it take? Even a rough expectation would help.
Topic: Safari & Web SubTopic: General Tags:
8h
Reply to Possible increase in false positive “Fraudulent Website Warning” detections in Safari (2026)
I have a theory, and given the current situation it looks quite realistic. I checked the DNS: skvoz.net → 89.169.35.79 (AS210644) skvoz.org → 91.184.241.229 (AS210644) lastfix.app → 5.182.87.37 (AS210644) lastfix.video → 5.182.87.37 (AS210644) AS210644 = AEZA-AS, AEZA GROUP LLC, RU We are both hosted on Aeza, and it turns out that since 2025 Aeza has been under sanctions: https://www.chainalysis.com/blog/ofac-sanctions-aeza-group-bulletproof-hosting-crypto-payments-july-2025/ I'm afraid that in this case support won't even do anything, since they are not allowed to work with companies on the sanctions list. The only option I see is to move to a different, "clean" provider and get new domains. And in parallel, keep trying to reach support to get the domains removed from those lists. This looks extremely sketchy and ugly from every angle, because I only just found out that our hosting provider is a bulletproof hosting operation and, on top of that, is under sanctions. And what's being blocked isn't the provider itself - it's our new domains. I don't think this is a coincidence - most likely this is exactly the cause.
Topic: Safari & Web SubTopic: General Tags:
Replies
Boosts
Views
Activity
3h
Reply to Possible increase in false positive “Fraudulent Website Warning” detections in Safari (2026)
Same problem here, with two domains. Timeline lastfix.app went live around July 12, 2026. Safari began showing the “Deceptive Website” warning shortly after. I moved the product to a new domain, lastfix.video, on July 24. It was flagged as well. A detail that may be relevant to others here: the verdict appears to follow redirects. During the migration I left a 301 from lastfix.app to lastfix.video. The new domain picked up the warning almost immediately, despite having no history of its own — it had existed for hours. I have since replaced the redirect with a static page containing an ordinary link instead. If anyone else in this thread migrated domains with a redirect in place, that may explain why their second domain was flagged too. Same verification results as yours Google Search Console: no security issues on either domain. Google Safe Browsing Transparency Report: no unsafe findings for either domain. Chrome opens both domains without any warning. Only Safari warns. Valid Let’s Encrypt certificates on both, correct chains. Regarding your first question — yes, Apple maintains an independent list. Safari stores the Safe Browsing data it downloads under two separate provider directories, one for Google and one for Apple, each containing its own threat lists. The Apple directory has its own social_engineering list, distinct from Google’s. So a domain can be listed by Apple while every Google list is clean. That is precisely what “Google reports safe, Safari warns” looks like from the outside, and it means checking Google Safe Browsing tells you nothing about the Apple verdict. Same pattern you describe Both of my domains were newly registered. Both were flagged within roughly one to two weeks of going live. Nothing about the content changed between the clean period and the warning appearing. Not all users see the warning — roughly half of the people I asked do, on different networks and devices. That is consistent with the list propagating to devices gradually rather than a per-device or per-network cause. I am preparing a Website Review submission now. Has anyone here had one actually resolved, and roughly how long did it take? Even a rough expectation would help.
Topic: Safari & Web SubTopic: General Tags:
Replies
Boosts
Views
Activity
8h