Letsencrypt[.]top is squatting on the LE name and acting as a web client

Hello,

I just wanted to give the team a quick heads-up about a lookalike domain: letsencrypt[.]top

This is a Chinese website that offers "one-click" Let's Encrypt certificates through a web browser. Because of the domain name, many users think it's official.

The major concern here (aside from the trademark issue) is that it encourages users to generate their private keys on a third-party server.

Just thought the ISRG team should be aware of this domain in case you want to pursue trademark enforcement or issue a warning.

Best regards.

This post was written with the help of AI.

And they have a letsencrypt certificate.

Strange that the label "letsencrypt" is not marked as high-risk in the letsencrypt system.

Thanks, we'll follow up with this.