Redirected to a suspicious page

What is the name of the domain?

canticos.pt

What is the issue you’re encountering

I usually send a weekly email to a mailing list containing links to the canticos.pt website. In recent days, when these links are clicked, we are redirected to a suspicious page. For example, the link that should open Cantemos cantemos ao Senhor - Laudate is instead opening https://gonging.royalt.shop/index.php?main_page=product_info&cPath=772&products_id=106214&previous_url=https%3A%2F%2Fwww.canticos.pt%2Fcantemos-cantemos-ao-senhor%2F However, this issue only occurs when accessing through Gmail on an Android smartphone. When using Gmail via the Chrome browser, on Mac or Windows, everything works fine.

However, this issue only occurs when accessing through Gmail on an Android smartphone. When using Gmail via the Chrome browser, on Mac or Windows, everything works fine.

Determine where from does the redirection come from, is it from some of the Cloudflare Settings which you’ve configured, is it from the Web application such as WordPress issue, or rather coming from the origin host/web server.

Without knowing the domain names, you could troubleshoot and track&trace to see which rule is executed, or rather where the redirection happens using the Trace tool from the Dashboard, adding the URL as an example with the GET request type as follows:

Maybe some Web browser cache at your Android phone? :thinking:

Otherwise, if there is a redirection happening, I wonder if you’ve got configured Mobile Redirection from/to sub-domain at Cloudflare as follows on the article from below? :thinking:

Furthermore, could be a catch somewhere in the:

  1. Page Rules - maybe left from old setup?
  2. Redirect Rules - if some particular configured
  3. Bulk Redirects - if used
  4. Workers - if you’ve used it on domainB since before?
  5. If used WordPress, maybe it’s making such redirection?
  6. Temporary Pause Cloudflare to see if the redirection happens on the origin host/server as well
  7. Cache - Purge Everything on both domains just in case

For sure what we’d need to do is check the HTTP headers to see as well.

Hopefully it is not malware.

Otherwise, could be your anti-virus software is redirecting you, or maybe some kind of a VPN on mobile or even Web browser extension?

This topic was automatically closed after 15 days. New replies are no longer allowed.