codecentric / spring-boot-admin

Admin UI for administration of spring boot applications
Apache License 2.0
12.38k stars 3.08k forks source link

Google Chrome flags docs.spring-boot-admin.com as a lookalike domain for spring.io #3619

Closed ParkerM closed 1 month ago

ParkerM commented 2 months ago

Today I visited the documentation website at https://docs.spring-boot-admin.com/3.3.3/ by clicking a link in the release notes, and Google Chrome displayed a low-confidence phishing warning that the domain may be imitating spring.io. This is the first time I've ever seen this kind of warning in Chrome, and it is presumably based on how often I browse pages at docs.spring.io and how rarely I browse pages at docs.spring-boot-admin.com. For that reason I doubt my issue can be easily reproduced, but I imagine the browsing patterns I've described are not uncommon among other SBA users.

Chrome warning that asks "Did you mean spring.io?"

Clicking "learn more" leads to a help page at https://support.google.com/chrome/answer/99020 with some information, and refers site owners to follow the instructions described in https://chromium.googlesource.com/chromium/src/+/master/docs/security/lookalikes/lookalike-domains.md

ulischulte commented 1 month ago

Hi @ParkerM Thanks for letting us know. We'll take a look at it.

ulischulte commented 1 month ago

Hi @ParkerM We just filed a manual review request since we're not owners of both sites. An approval might take some time. Regards, Uli

ulischulte commented 1 month ago

We just received an answer and the lookalike warning should be removed anytime soon.