Lookalikes on Hosting Platforms: yourbrand.pages.dev
No registrar, no registration record, no cost. A platform name is the cheapest lookalike there is. Illustrative lookalikes in this guide use the reserved .test ending, so that no real registration is named.
A hosting-platform lookalike is a real brand name claimed as a subdomain of a public hosting platform, so that example.pages.dev, example.netlify.app or example.github.io stands in for example.com without any domain being registered.
This guide covers why platform names sit outside the registration system, the roughly forty platforms a generator tries, why the checker makes one request to such a name and no other, how these findings are ranked, and how to get one removed.
- Family in a report
- Hosting platform name
- Sample
- example.pages.dev
- Candidates for a six-letter domain
- 347 of 3,001
What a platform lookalike is
Public hosting platforms give every project a name under their own domain: something.pages.dev, something.netlify.app, something.github.io, and dozens more. The platform's domain is a public suffix, one under which the public can, or historically could, directly register names, and the Public Suffix List records it as such. A lookalike claims your brand as the project name. Nothing is registered with a registrar, so there is no RDAP record, no registration date, no registrar to complain to.
The generator tries about forty platforms, which yields 347 candidates for a six-letter name, the fourth-largest family in a check.
| Family | Example | Registration record | Candidates for a six-letter label |
|---|---|---|---|
| Hosting platform name | example.pages.dev | None; the platform owns pages.dev | 347 |
Why the checker makes one request here
Every other family is checked without contacting the suspect name: registry, DNS, certificate logs, passive records. Platform names are the single exception, and the reason is DNS itself. A platform answers DNS for every possible subdomain of its domain whether or not anyone has claimed it, so resolving example.pages.dev proves nothing. The checker therefore sends one request to the name to learn whether a project exists there, and reads nothing from the response beyond that fact. The methodology page states the exception and the reason.
What a claimed platform name usually is
Often it is yours: development and staging sites live on these platforms, and the Possibly yours tag cannot apply because there is no registrar to match, so a report may list your own preview site. Otherwise it is a project by someone who chose the word, or, in the case that matters, a phishing page that borrows the platform's certificate and reputation. A platform name always has a valid certificate, issued by the platform, so a certificate is no signal here; the age of the claim and what the passive record shows are.
How the checker finds and ranks it
A finding's review priority is a published rule, not a score. A name with an address or a mail record is active; active names registered under 90 days ago are Elevated, and so are active names under a year old that carry an impersonation keyword. Anything else that is active or has a registry record is Review, a name with no registry record and no DNS answer is Low signal, and a lookup the registry refused stays Unknown rather than being counted as a negative.
With no registry record, a claimed platform name is active by its address and is ranked on that and on any keyword it carries; the report says Hosting platform name in the pattern column so the missing registration is understood rather than read as Unknown.
What to do with one
If it is your own preview site, tag it Owned. If it is not, the route is the platform, not a registrar: every major platform has an abuse form, and they act on impersonation quickly because the name is theirs. The reporting guide has the addresses. Keep the report; do not open the page.
Common questions
- Why is there no registrar for example.pages.dev?
- Because pages.dev belongs to the platform and example is a project name under it, created without any registration. The Public Suffix List records the platform domain as one the public can claim names under.
- Does the checker visit the platform name?
- It sends one request to learn whether a project exists there, because the platform answers DNS for every possible name and resolution alone proves nothing. It reads nothing else, and this is the only family where any request is made.
- Why does a platform lookalike always have a certificate?
- The platform issues one for every project automatically. A certificate is therefore no signal for this family; age and passive records are.
- Who do I report a platform lookalike to?
- The platform's abuse form. Platforms act on impersonation under their own domain quickly, and there is no registrar involved.
Sources and further reading
Keep reading in Typosquatting patterns
- Transposition Typosquatting: Two Letters Swapped
- Omission Typosquatting: One Letter Missing
- Insertion Typosquatting: One Letter Too Many
- Repetition Typosquatting: The Doubled Letter
- Keyboard Typosquatting: The Neighbouring Key
- Homoglyph Domains: Letters That Look Alike
- Combosquatting: Your Brand Plus a Keyword
- TLD Squatting: Your Name Under a Different Ending
- Subdomain and Hyphen Lookalikes: ex.ample and ex-ample
- Bitsquatting: Domains One Bit Away