https://discord.com
162.159.136.232 · Cloudflare, Inc.
Toronto, Canada
9307 days
200 · 30.1s
Valid· WE1, Google Trust Services, US
COMPLETED
No KB/IOK detections were recorded for this scan.
Technology · 6/3/2026
Discord appear to be the presented brand on the page. The final URL is the official discord.com, and the page title matches Discord’s branding. However, the scan evidence reveals a large number of off-domain API endpoints, external scripts, and a SPA-like structure with many network requests and POST endpoints to Discord API, which could be benign for the real site but also warrants caution due to potential credential capture in a SPA context. The screenshot shows Discord branding, but the presence of on-page widgets and cross-origin assets could be leveraged for abuse; no explicit credential harvesting form is visible in static HTML, but the SPA could render credential fields dynamically. Overall, there is no definitive impersonation signal against Discord’s official domain, but the evidence suggests heavy third-party asset loading and possible credential collection risk via dynamic UI.
Capture
Stages: 3
Canonical: Late Render (+3s)
Changed: No
Credential Signals
Forms: 0
Password fields: 0
Late-stage login UI: No
Resource Signals
Resources: 178
Hosts: 11
Domains: 11
Suspicious Endpoints
hxxps://discord[.]com/
hxxps://discord[.]com/w/assets/10907dcf2b5e3687b658036d0f4dea64aa95512c/styles.css
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/678a4b31695af76b1f713594_Discord_Nelly_Pose2_Flying%201.webp
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/css/discord-2022.shared.b80954b92.min.css
hxxps://discord[.]com/webflow-scripts/head.js
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/js/discord-2022.schunk.36b8fb49256177c8.js
Off-Domain Posts
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/678a4b31695af76b1f713594_Discord_Nelly_Pose2_Flying%201.webp
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/css/discord-2022.shared.b80954b92.min.css
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/js/discord-2022.schunk.36b8fb49256177c8.js
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/js/discord-2022.schunk.c42549641b7d4501.js
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/js/discord-2022.schunk.03875b26d8942e7b.js
hxxps://cdn[.]prod[.]website-files[.]com/6257adef93867e50d84d30e2/67110a452ee74d65f90c1dc0_ABCGintoDiscord-Medium.woff2
The domain is the official Discord domain and shows legitimate branding. However, the scan highlights heavy cross-domain resource loading and dynamic UI rendering that could be leveraged for credential collection in a malicious context if presented on a spoofed site. The POST calls to Discord API endpoints appear normal for a live Discord page, but the presence of many external assets and a complex script stack warrants monitoring for unusual behavior. Given the evidence, this likely represents the legitimate Discord site, but the observed SPA behavior and third-party assets should be monitored for potential abuse or misrepresentation if encountered on impersonating domains. Recommend continued observation and security monitoring; no definitive phishing indication on the official domain based on the current signals.
Monitor