#Deceptive Site Warning on Autentik server used as traefik middleware

1 messages · Page 1 of 1 (latest)

quaint zealot
#

I just deployed authentik on 2 different domains. auth.domain1.com and auth.domain2.com. and they are both getting the deceptive site warning (in safari, chrome, firefox, and edge), specific to the top-level authentik subdomain (e.g. https://auth.domain1.com/ ). I must have done something wrong to get this to occur on both sites. I'm using Authentik as a trafik middleware to control access to self-hosted services--there is not public-facing content that is not autheticated through authentik. Does anyone have any ideas what I did wrong? or what might be making the authetik server site look like phishing?

cinder gazelle
#

From my expirience this usually occurs if your domain looks similar to other popular domains (Typosquatting).
Could this be the case?

I had my own domain and then used an online shop with domain.shopprovider.tld which then got a similar warning which disappeared after some time.

quaint zealot
abstract granite
#

just posted this in #general about when I had the same issue: I feel like it's worth mentioning that for whatever stupid reason, shortly after first deploying Authentik, my login page almost immediately ended up flagged by Google. I requested a review and they removed the flag almost as quickly as it came.

There was nothing public hosted on my domain for nearly 10 years (and nothing ever hosted on auth.$mydomain before), and my IP is from a consumer Verizon FiOS connection. I also never changed anything on the login flows except maybe putting my project name (perchnet, nothing weird or nefarious) into the name and adding an option to passwordless sign in with a WebAuthN "passkey"

Overall given the above, it's probably pretty safe to say that there's some sort of automatic heuristic detection that doesn't love Authentik

quaint zealot