Don't trust this domain. It redirects to a familiar Concur login page, but the domain itself is invisible β it doesn't even have a WHOIS record. That's exactly the kind of setup phishing relies on. Stay away and access Concur only through its official URL.
What you should do now
Don't panic. These steps limit the damage, and the sooner you take them the better.
1
Don't enter any details
No passwords, card numbers or personal information β even if the site looks professional.
2
Close the tab
Especially if you got here from an email, text message or social media ad.
3
Already paid? Call your bank
Contact your bank or card provider right away. They can often stop or reverse a recent payment.
4
Warn others
Report the site and share this check with anyone who sent you the link.
Cross-referenced 18 live signals from Google Safe Browsing, VirusTotal, WHOIS and more on Jul 25, 2026.How we score β
Where the score comes from
We look at six areas. Here's how concur.criteois.com did in each.
85
Security
The connection is encrypted with modern TLS and a reputable certificate authority, and no malware or phishing flags are attached. That's the one thing this domain gets right.
5
Identity
This domain doesn't appear in the public WHOIS registry at all. For a site that redirects to a login page, that's a fundamental failure β you have no way to know who registered it or when.
50
Reputation
The domain isn't blacklisted, but it has no history in the Wayback Machine, no traffic rank, and no external reviews. It's essentially a blank slate, which is unsettling for something that wants to handle authentication.
20
Transparency
The site itself is just a redirect β there's no content, no contact information, no branding. It gives you nothing to judge who's behind it.
80
Compliance
Since the domain merely redirects to a legitimate Concur login page, the absence of legal pages on this specific domain isn't a compliance issue. The real service handles those obligations.
70
Infrastructure
DNS resolves correctly, the server is on Microsoft's network with Akamai storage, and basic files like robots.txt exist. Nothing broken, but nothing exceptional either.
What we checked
The 18 signals behind this report.
Security & Transport
Certificate Issuer
DigiCert Inc
Google Web Risk
Clean
Redirect Check
Redirects away
SSL Certificate
Valid
Server
AkamaiNetStorage
TLS Version
TLS 1.3
Identity & WHOIS
Branding
Missing
Infrastructure & DNS
DNS Blacklists
Clean
DNS Resolution
1 IP(s)
DNSSEC
Not enabled
Email (MX Records)
None
Hosting Network (ASN)
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK
Reputation & Reach
Sitemap
Misconfigured
Tranco Rank
Not ranked
Trustpilot
No Trustpilot profile
Web Archive History
No archive found
robots.txt
Present
Other
Site Redirect
Redirects to eu1.concursolutions.com
Think this verdict is wrong?
Site owners can request a fresh scan. Scores update automatically as signals change.
concur.criteois.com redirects to a Concur login page, but that's not a reason to trust it. Legitimate SaaS subdomains for authentication are registered with clear ownership records. This domain has no WHOIS record at all β it's as if it doesn't officially exist. That's a huge red flag for a site that wants you to type in a password. Phishing operations often use exactly this trick: redirect to a real login page while the suspicious domain captures your credentials along the way. If you need to access Concur, type the URL directly into your browser. Don't follow links from an unknown domain like this one. Is concur.criteois.com a scam? The evidence leans heavily that way. The safest move is to avoid it completely.