This site is dangerous to use in its current state. It's completely unreachable via a secure connection, and the TLS handshake failure means any data you tried to send would be unprotected or simply not delivered. While it's a subdomain of the legitimate MELCloud service, this particular server is misconfigured and should not be trusted for any purpose.
What you should do now
Don't panic. These steps limit the damage, and the sooner you take them the better.
1
Don't enter any details
No passwords, card numbers or personal information β even if the site looks professional.
2
Close the tab
Especially if you got here from an email, text message or social media ad.
3
Already paid? Call your bank
Contact your bank or card provider right away. They can often stop or reverse a recent payment.
4
Warn others
Report the site and share this check with anyone who sent you the link.
Cross-referenced 25 live signals from Google Safe Browsing, VirusTotal, WHOIS and more on Jul 22, 2026.How we score β
Where the score comes from
We look at six areas. Here's how production.receiver.melcloud.com did in each.
10
Security
The site fails to establish a secure connection β no HTTPS, a TLS handshake failure, and it's completely unreachable from a browser. For any server that handles data, this is a critical failure.
70
Identity
This is a subdomain of melcloud.com, a known cloud service from Mitsubishi Electric. The lack of direct WHOIS data for the subdomain is expected and not a concern.
60
Reputation
No blacklist hits and no history in the Wayback Machine, which is normal for a backend endpoint that isn't meant to be crawled. There's no evidence of abuse, but also no track record.
80
Transparency
Backend servers don't need about pages or contact info, so the absence of these is perfectly normal. The site is not designed for public interaction.
80
Compliance
Legal pages like privacy policies are not relevant for a non-consumer-facing endpoint. No compliance gap here.
20
Infrastructure
Hosted on AWS, which is fine, but the missing SSL, email setup, and security headers are serious for a production server. The site is effectively broken from a security standpoint.
What we checked
The 25 signals behind this report.
Security & Transport
Google Web Risk
Clean
SSL/TLS
No HTTPS
Security Headers
0 of 6
Site Reachable
Unreachable
Identity & WHOIS
About Page
Not found
Branding
Missing
Business Disclosure
Not found
Contact Info
Unable to check
Legal Pages
Unable to check
Infrastructure & DNS
DNS Blacklists
Clean
DNS Resolution
3 IP(s)
DNSSEC
Not enabled
Email (MX Records)
None
Hosting Network (ASN)
AS16509 AMAZON-02
Page Load Time
71ms
Reputation & Reach
Page Heading
Server Error
Page Title
403 - Forbidden: Access is denied.
Sitemap
Unable to check
Social Media Presence
Unable to check
Structured Data
None found
Tranco Rank
Not ranked
Trustpilot
No Trustpilot profile
Web Archive History
No archive found
Website Status
Bot protection detected
robots.txt
Not found
Think this verdict is wrong?
Site owners can request a fresh scan. Scores update automatically as signals change.
production.receiver.melcloud.com is a subdomain of the MELCloud platform, which is a legitimate cloud service for Mitsubishi Electric HVAC systems. But this particular endpoint isn't meant to be visited by people β it's a backend server, likely an API or data receiver. The problem is that it's completely broken from a security perspective. There's no SSL certificate, the connection fails with a TLS handshake error, and the server returns a 403 Forbidden error to any attempt to reach it. For a production server that might be handling data, this is a serious red flag. Even if you're a developer trying to integrate with this service, you should not send any data to this endpoint until it's properly secured. The lack of encryption means anything transmitted would be in plain text, and the connection failure suggests the server isn't configured correctly. There's no indication this is a scam β it's just a poorly configured server that isn't safe to use right now.