Typosquatting.ai
Your first step

Check a domain

Enter the domain you want to protect. The engine generates thousands of variations, resolves every one, and reports the names that exist with the records behind them.

No account needed. A check takes one to three minutes.

  • Registry RDAP
  • DNS over HTTPS
  • Certificate logs
  • Passive web records

Not ready to run one? Read a finished report or see how results are produced.

What a check covers

The discovery engine builds thousands of candidate names from the registrable form of your domain: missing, doubled, swapped and inserted letters, keyboard-neighbour substitutions, Latin and Cyrillic lookalike characters, impersonation keywords such as login and secure in several positions, about 180 alternative endings, and the same name on common public hosting platforms. Every candidate is resolved over DNS, names that are delegated but not yet live are kept as dormant, and certificate-transparency logs are searched for more. The highest-priority findings are then looked up in the registry’s RDAP service, in DNS for address, mail and nameserver records, and in a passive search for earlier observations of the host.

What you get back

A table with one row per variation: registration status, the registrar and creation date where the registry discloses them, the addresses and mail routing that DNS returns, whether a public scan has observed the host, and a review priority of Elevated, Review, Low signal or Unknown together with the rule that produced it. Each row expands to show the evidence behind its label, and a saved report in your panel lists what changed since the previous run.

What it cannot tell you

Similarity is not proof of intent. A registered lookalike may be a defensive registration, a coincidence, or an unrelated business that happens to share the letters. The checker never loads a suspect page to read what is on it, so it cannot see page content, and it resolves at most the first 2,970 candidates rather than every possible script, ending or subdomain. Treat Elevated as the row to look at first, not as a verdict about the owner.

What happens to the domain you enter

A check runs as a background job. The job record and the finished report are stored for 24 hours so the results page can show them, then deleted by a scheduled sweep; individual record lookups are cached in server memory for 15 minutes. The generated variations go to the DNS resolver, the registry’s RDAP service and the passive search from our servers, so those providers see our address rather than yours. The domain does appear in the page address, so it may be in your browser history.

The four sources, and what each answers

  • Registry RDAPCreation date, registrar and status
  • DNS over HTTPSA, AAAA, MX and NS answers
  • Certificate logsNames as certificates are issued
  • Passive web recordsWhat a scanner saw previously

Every pattern, source, timeout and risk rule is published on the methodology page.