Security Scan Report: ortto.mail.elskling.se

Site favicon
Submitted: Sep 16, 2026, 10:42:32 AMCompleted: Sep 16, 2026, 10:42:53 AMpubliccompleted

This website contacted 19 IPs in 2 countries across 8 domains to perform 33 HTTP transactions. The main domain is ortto.mail.elskling.se and was registered 7 years ago.

Submitted URL: https://ortto.mail.elskling.se/-/m/s/preferences?k=CmVsc2tsaW5nc2UAapBPje3If066NAtgaqpw-hL8RPKuV1Y8v_AY

AI Security Verdict

Safe Website

Confidence: 88%

1
Risk Score

Legitimate email preferences page for the long-established Elskling SE brand; no forms, no credential collection, and no threat-intel, malware, or phishing indicators detected.

Safety Factors
Established domain aged ~19 years with matching self-branding
No credential or payment collection on the page
No threat-intelligence, malware, or phishing indicators
Content is a standard unsubscribe/preferences page for a legitimate marketing sender
Domain age information unavailable

Details

Page Title

Email preferences - Elskling SE

Scan Type

public

Domain Name Analysis

Domain 'ortto.mail.elskling.se' uses the Swedish country-code top-level domain (.se) with subdomain 'ortto.mail'. The second-level label 'elskling' is 8 characters long with two vowels and 6 consonants. Breaking it apart gives two words: els, kling. Median word length comes out to four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ortto.mail.elskling.se/-/m/s/preferences?k=CmVsc2tsaW5nc2UAapBPje3If066NAtgaqpw-hL8RPKuV1Y8v_AY

Page Load Overview

2.77s
Total Load Time
1.4 MB
Total Size

Language Analysis

Primary Language

🇸🇪Swedish
Code: sv
Confidence:44%
Script:Latin
Direction:ltr

Detection Details

Text Length:471 chars
Detector Agreement:50%

Website Classification

Primary Category

finance banking42% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

finance banking
42%
technology software
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1565.9.130.118Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
13.73.199.118Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
13.23.199.68Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
13.141.179.142Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
13.18.187.22Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
13.23.106.204Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
13.147.160.202Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
13.124.109.78Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
13.139.207.11Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
3319--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18642CEB756E654129B42A9DD42153315D133883EECF0BCC3FCD4E81CB4B5FA98A9E298

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:hzz9s86jUd9fg6vDD85aJxDuMmoqAXUqwDYc:hzS86jYHDumEq8

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12818:EyKyiREEIQdsAs3UsKYYBAARowwSnJBmhSJAgQTgHHSFIAQBThTUAA0CUjgSKhSAp0nEBEqMmBZUZDUzCEIO0AiaqWFNEQgA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7c7c7cfcfffffff
Perceptual Hash:b13367c68ecec630
Difference Hash:4a0c1c1010020202
Wavelet Hash:e0c0c0ccdcfcf0f0
Color Hash:#d22d93

Other Hashes

Crop Resistant:4a0c1c1010020202

Scan History

Scan history not available

Unable to load historical scan data