This domain is not a typical consumer website. It's a backend service subdomain that is currently unreachable and has no HTTPS. While it likely belongs to Salesforce infrastructure, the broken security and lack of functionality mean you should not attempt to use it for any purpose. Treat it as untrustworthy until it shows signs of being a properly secured, accessible service.
What you should do now
Don't panic. These steps limit the damage, and the sooner you take them the better.
1
Don't enter any details
No passwords, card numbers or personal information β even if the site looks professional.
2
Close the tab
Especially if you got here from an email, text message or social media ad.
3
Already paid? Call your bank
Contact your bank or card provider right away. They can often stop or reverse a recent payment.
4
Warn others
Report the site and share this check with anyone who sent you the link.
Cross-referenced 22 live signals from Google Safe Browsing, VirusTotal, WHOIS and more on Jul 22, 2026.How we score β
Where the score comes from
We look at six areas. Here's how global-core1.sfdc-lywfpd.svc.sfdcfc.net did in each.
15
Security
The site is completely unreachable over HTTPS and the connection is reset, which is a critical failure for any service that expects to be accessed. No malware flags exist, but the lack of basic encryption makes this unusable for any secure interaction.
50
Identity
The subdomain itself has no WHOIS record, which is normal for subdomains. The naming pattern strongly suggests it belongs to Salesforce (sfdcfc.net), a well-known company, but we have no direct verification of ownership for this specific endpoint.
50
Reputation
No blacklists or Google Web Risk flags, which is positive. However, the domain has no history in the Wayback Machine and no external trust signals, which is expected for a new or internal subdomain.
70
Transparency
There is no about page, contact info, or social media presence, but for a backend service endpoint that is not intended for consumer use, this is not a red flag. The lack of transparency is irrelevant here.
70
Compliance
No privacy policy or terms of service are present, which would be a problem for a consumer-facing site, but this appears to be an internal infrastructure subdomain where such legal pages are not expected.
50
Infrastructure
DNSSEC is enabled and DNS resolution works, but the site is unreachable and returns a 404 error. Hosted on Amazon AWS, which is reputable, but the lack of HTTPS and the connection reset indicate a misconfigured or non-functional service.
What we checked
The 22 signals behind this report.
Security & Transport
Google Web Risk
Clean
SSL/TLS
No HTTPS
Security Headers
0 of 6
Site Reachable
Unreachable
Identity & WHOIS
About Page
Not found
Branding
Missing
Business Disclosure
Not found
Contact Info
Not found
Legal Pages
Missing
Infrastructure & DNS
DNS Blacklists
Clean
DNS Resolution
3 IP(s)
DNSSEC
Enabled
Email (MX Records)
None
Hosting Network (ASN)
AS16509 AMAZON-02
Page Load Time
346ms
Reputation & Reach
Sitemap
Unable to check
Social Media Presence
None found
Tranco Rank
Not ranked
Trustpilot
No Trustpilot profile
Web Archive History
No archive found
Website Status
HTTP 404
robots.txt
Not found
Think this verdict is wrong?
Site owners can request a fresh scan. Scores update automatically as signals change.
This domain looks like a technical subdomain of Salesforce's infrastructure, not a website you'd visit to buy something or sign up for a service. But that doesn't mean you should trust it blindly. The site is completely unreachable over a secure connection, and even the HTTP version returns a 404 error. For any legitimate Salesforce service endpoint, you'd expect HTTPS to be working properly. The lack of any web archive history or social presence is normal for a backend component, but the broken security is a clear warning. If you came across this URL in an email or a configuration file, do not click it or enter any data. It's not a functional consumer site, and there's no evidence it's safe to interact with. Stick to known, verified Salesforce domains like login.salesforce.com instead.