This company has verified ownership of the profile and can respond to reviews.
Verified Safe
Current checks include security-provider warnings. Review the detected warnings and supporting trust evidence before relying on the site.
Trust signal radarNormalized trust signals for checkyout.appDomain Maturity: 159 daysDomain MaturityWarning Cleanliness: 4 detectionsWarningCleanlinessSafety Level: 0 negative tags, 2 warning signalsSafetyLevelPositive Signals: 3 positive signalsPositiveSignalsPopularity: Estimated low traffic without Tranco or social profile dataPopularityTrust Zone: .appTrust ZoneOperational Signals: 4 detected servicesOperationalSignalsLocation Credibility: Hosting country CHLocation Credibility
Figure 1. Trust signal radar for checkyout.app. Larger shaded area indicates stronger trust signals.
How we scored checkyout.app
On-page mentions:
Travel Service
Tech signals:
React Platform, Next.js Framework, Extended Data
Positive signals:
the domain owner has claimed this profile
an active SSL certificate (3 months)
multi-language support
extended data
Negative signals:
security-provider warnings
a relatively new domain (5 months)
Context signals:
content related to travel-related services
Last checked September 1, 2026 at 6:36 PM by
Gridinsoft Trust Model v2.5.3
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260901183616-d6cdd0a7
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Safe
Evidence basis
First-party site analysisExternal vendor intelligence: Contradictory context โ not used for this decision
The independent first-party review did not reproduce phishing, credential theft, malware delivery, an unrelated redirect, or another current harmful behavior on checkyout.app. The exact host, public service pages, login and contact surfaces, company identity, parent-domain namespace, DNS and TLS state, repeated content, and public URL-scanner history were consistent with the stated CheckYout hospitality-operations SaaS. Remaining adverse records were contradictory domain blacklist categories without a reproducible malicious object.
Analyst findings
Info4
Info01
No current phishing flow was reproduced
The exact host and reviewed public pages consistently presented the self-branded CheckYout SaaS. Navigation remained on the expected service, and the review did not find unrelated brand impersonation, an external credential receiver, or a deceptive verification flow.
Info02
Public service and company identity were consistent
The product pages, contact data, imprint, login, parent-domain namespace, and independent company records matched the stated Swiss hospitality-operations SaaS and its operator.
Info03
Domain blacklist labels did not identify a malicious object
The remaining warnings were domain-wide reputation categories. The reviewed public indexes did not identify an exact malicious URL, file, payload, hash, external credential receiver, redirect chain, or harmful execution that could be reproduced.
Info04
No specific malware sample was identified
The live review, repeated navigation, public URL-scanner history, threat-intelligence searches, and archive checks did not provide a specific malware file, payload, URL, or hash for checkyout.app.
Review 8 documented observations
View evidence
01Redirect
The exact host returned the expected CheckYout service over HTTPS. Plain HTTP and www redirected only to the canonical HTTPS root, and three repeated HTTPS requests produced the same destination and identical response bytes.
HTTP status200
Final URLhttps://checkyout.app/
Redirect destinationhttp://checkyout.app/ redirected to https://checkyout.app/
Redirect destinationhttps://www.checkyout.app/ redirected to https://checkyout.app/
Analyst observationThree repeated root requests kept the same final host and returned identical content; no rotating or unrelated destination was observed.
02Content
The root, English service pages, contact page, imprint, privacy page, and login page consistently described a CheckYout vacation-rental checkout and cleaning-notification SaaS. The reviewed public content did not imitate an unrelated brand or present a failed-delivery, account-verification, payment, or recovery-seed lure.
Page elementGast reist frรผher ab? Reinigungsteam wird per WhatsApp informiert
Page elementAnmelden โ CheckYout
Page elementContact & Support โ CheckYout
Page elementImpressum โ CheckYout
Page elementDatenschutzerklรคrung โ CheckYout
Analyst observationThe reviewed public pages did not initiate an automatic executable, archive, installer, or other file delivery.
03Content
The public imprint and contact pages identified TEAM M digital GmbH, Mathias Bรผschlen, the Swiss address, and UID CHE-451.095.935. Public company and professional indexes independently matched the company name, address, UID, and managing person; this identity context corroborated the stated service but was not treated as security proof by itself.
HTTP status200
Page elementTEAM M digital GmbH
Page elementCHE-451.095.935
Page elementTrogenstrasse 6, 3653 Oberhofen am Thunersee, Switzerland
Public artifact URLhttps://www.zefix.admin.ch/de/search/entity/list/firm/1402564
Analyst observationIndependent public company-directory and professional-index records matched TEAM M digital GmbH, UID CHE-451.095.935, the Oberhofen address, and Mathias Bรผschlen.
04Navigation
The appealed host is the registrable parent domain itself. Public certificate records exposed only the root, www, and cleaners hosts; www canonicalized to the root, while cleaners returned a self-branded CheckYout cleaning-team login without an unrelated redirect.
DNS factCertificate transparency names: checkyout.app, www.checkyout.app, cleaners.checkyout.app.
HTTP status200
Final URLhttps://cleaners.checkyout.app/login
Page elementCleaners โ powered by CheckYout
Analyst observationNo separate higher registrable parent domain exists for checkyout.app; the exact appealed host and parent domain are the same scope.
05TLS
The root resolved to its current Vercel deployment, presented a valid certificate for checkyout.app, and returned transport and browser hardening headers consistent with the reviewed application.
DNS factcheckyout.app resolved to 216.150.1.1 during the review.
Certificate factThe Let's Encrypt certificate covered checkyout.app and was valid from 2026-07-26 through 2026-10-24.
Page elementContent-Security-Policy restricted form submissions to self and framing ancestors to none.
06Historical content
Public URL-scanner and search indexes preserved a consistent CheckYout service from March through August 2026. Retrieved records showed the root service and the cleaners login without a concrete harmful path, payload, file, hash, or result-level malicious verdict.
Analyst observationThe urlscan search index returned 11 records dated 2026-03-29 through 2026-08-22, including repeated root scans and the cleaners subdomain.
Analyst observationRepeated indexed root scans showed HTTP 200, the CheckYout product title, Vercel hosting, and the canonical checkyout.app destination.
Analyst observationWayback CDX returned no successful captures for the root or www host, so absence of archive material was treated as an evidence limitation rather than a clean result.
Analyst observationSearch indexes surfaced current product, FAQ, contact, cleaning-team, and blog pages consistent with the same service and did not surface a preserved exact malicious object.
07Historical content
Public threat-intelligence and sandbox searches did not surface a concrete malicious object for the exact host. OTX returned no pulse, OpenPhish had no exact match, and public sandbox searches did not expose an exact-host harmful execution report; authentication-only or unavailable sources were treated as unknown.
Analyst observationOTX returned zero pulses for checkyout.app and www.checkyout.app.
Analyst observationThe OTX URL list contained root and www HTTP 200 observations and no Google Safe Browsing match in the retrieved records.
Analyst observationOpenPhish contained no exact checkyout.app match at the recorded review time.
Analyst observationURLhaus and ThreatFox public APIs required authentication during the check; Common Crawl and crt.sh were unavailable, so those sources were recorded as unknown rather than clean.
Analyst observationExact-host searches of public sandbox and URL-analysis indexes did not surface a report with a specific harmful execution trace, download, payload, or hash.
08Limitation
No specific malicious URL, file, payload, hash, external credential receiver, unrelated redirect chain, or harmful execution trace was identified. The remaining adverse evidence consisted of domain-level blacklist categories rather than an observable malicious object.
Analyst observationThe ticket and reviewed public records did not provide an exact harmful URL, file, payload, or hash for object-specific reproduction.
Analyst observationCurrent external labels included phishing, malicious, and suspicious categories at the domain level but did not expose a reproducible malicious sample in the reviewed sources.
Scope and limitations
The verdict applies to the public root, representative public pages, login surfaces, observed parent-domain namespace, redirects, DNS, TLS, and public index records reviewed at the recorded time; authenticated customer accounts, private data, server-side files or logs, and future changes were not assessed.
No exact guest checkout token or cleaning confirmation token was supplied for object-specific review. The review therefore does not certify every private or customer-specific workflow instance.
Wayback returned no successful captures, and several public intelligence APIs were unavailable or authentication-only. Those sources were treated as unknown rather than clean; urlscan and public search indexes supplied the available historical view.
The absence of a reproducible object in the reviewed public sources does not prove that no historical abuse ever occurred; it means the current Phishing classification was not supported by reproducible first-party evidence in the reviewed scope.
This domain was registered March 25, 2026 at 10:00 PM through the company Ascio Technologies, Inc
WHOIS registrant details are private. Separately, the business has verified control of its Gridinsoft profile.
Complaint contact not found.
About checkyout.app
We reviewed checkyout.app and found mostly positive signals. Current checks lean toward a legitimate, lower-risk profile, although a few caution points still keep it short of a fully verified standing. The current trust score is 89/100. Key signals include security-provider warnings. Verify key details before sharing personal information or relying on the site for important actions.
Figure 2.
Website screenshot for Checkyout.app.
2026-09-01 21:36:05
FAQ
Is checkyout.app safe?
Based on current analysis, checkyout.app appears to be generally safe. The final verdict also reflects manual expert review. Basic verification is still reasonable before relying on the site.
Why does checkyout.app look trustworthy?
Key factors include registrar information (Ascio Technologies, Inc), hosting in US, a relatively new domain (5 months), and content related to travel-related services. The trust score blends security detections, domain and infrastructure signals, and on-page behavior patterns. Taken together, these factors support a mostly positive trust assessment, although routine verification is still reasonable.
Checkyout Digital Footprints
A structured view of the site's detected themes, page signals, and related online footprint elements.
Travel Service
Registration Form
Automated page analysis detected form or data-entry functionality on checkyout.app. Forms can involve user-submitted information, so verify ownership and privacy terms before entering data.
Cookie Consent
This site implements a cookie-consent interface for managing tracking and data-collection preferences.
React Platform
The checkyout.app website is built using React, a popular JavaScript library for creating interactive user interfaces.
Multilanguage
The website provides multi-language support, demonstrating international accessibility and commitment to diverse user populations. Multi-language implementation typically indicates professional development standards and global operational scope, representing a positive trust indicator.
Next.js Framework
Social Media Links
The presence of social media links on the website indicates that it references social media accounts. This signal alone does not confirm ownership or authenticity of those profiles.
Extended Data
checkyout.app includes extended structured page data about entities, offerings, or site metadata.
Young Domain
This site was registered recently, which limits historical reputation data and long-term trust signals.
Claimed Company Profile
The company behind this site has claimed its profile in the Gridinsoft portal and provided verified ownership details.
External provider warnings: 4/28
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
ADMINUSLabs
Malicious
Chong Lua Dao
Malicious
SOCRadar
Phishing
ESET
Suspicious
External provider results for Checkyout.app, last checked September 1, 2026.
โ VirusTotal
Domain Information
CreatedMarch 25, 2026 at 10:00 PMExpires: March 25, 2027 at 10:00 PM
Domain Age5 monthsRecently Registered
RegistrantCH (Switzerland)
RegistrarAscio Technologies, Inc
Top Level Domain.appGeneric TLD
Technical Details
IP Address216.150.1.1
Hosting ProviderAS16509 Amazon.com, Inc.Walnut, California, US
SSL CertificateYR2TLS 1.3 ยท Valid for: 3 months ยท from July 26, 2026 at 7:22 PM ยท to October 24, 2026 at 7:22 PM
Name Serversns.hostpoint.ch ns2.hostpoint.ch ns3.hostpoint.ch
Content Analysis
Website titleGast reist frรผher ab? Reinigungsteam wird per WhatsApp informiert
Website descriptionGast scannt beim Check-out den QR-Code, dein Reinigungsteam bekommt sofort eine WhatsApp und kann Stunden frรผher starten. Fรผr Ferienwohnungen & Airbnb.
Detection SignaturesThese signatures are used to generate the security fingerprint below.
Travel ServiceRegistration FormCookie ConsentReact PlatformNext.js FrameworkSocial Media Links
Verified ServicesThis domain has been verified by the following legitimate services and organizations, confirming authentic ownership and proper email security configuration.
DMARC
Email authentication and reporting protocol.
Google Verification
Domain ownership verified by Google.
Seobility
Twilio
Cloud communications platform (SMS, voice).
Security FingerprintUnique identifier based on site analysis
If you own Checkyout.app and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about checkyout.app, the fewer chances they have to deceive someone else.Help others evaluate checkyout.app by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about checkyout.app, the fewer chances they have to deceive someone else. Help others evaluate checkyout.app by sharing this page on social media!