Typosquatting.ai
BRAND PROTECTION

See every domain built to look like your brand.

Lookalike names are cheap to register, quick to certificate and aimed at the people who already trust you. The work is finding them early and knowing which few are worth an hour.

Why brand impersonation is hard to stop

Not because the names are hidden. Because there are too many of them and most are harmless.

It moves faster than a quarterly review

A name can be registered, certificated and serving a page in a day. A review cycle measured in months finds it after your customers do.

One brand, thousands of plausible names

A single six-letter domain yields around 3,001 candidates. Buying that space is not a strategy, and reading it by hand is not either.

Most findings are not attacks

Defensive registrations you forgot, unrelated businesses, parked names. A process that treats all of them as urgent gets abandoned in a week.

What a check surfaces

  • DNS over HTTPS

    Registered lookalikes

    Names that exist, not names that could. Every candidate is resolved before anything reaches your report.

  • Certificate transparency

    Names being prepared

    A certificate is usually issued before a page appears, so the logs give the earliest public warning.

  • MX records

    Variations configured for mail

    Publishing mail routing is a deliberate act. A lookalike that can receive mail has had a decision made about it.

  • Registry RDAP

    Names that are already yours

    A variation sharing your registrar and nameservers is tagged Possibly yours, so your own defensive registrations stop costing attention.

How it works

  1. 01

    Check

    Enter a domain. About 3,001 candidate names are generated across twenty pattern families, roughly 180 endings and forty hosting platforms, and every one is resolved over DNS.

  2. 02

    Watch

    Put the domain on a watchlist and it is re-checked daily, with certificate transparency logs searched every thirty minutes so a name being prepared reaches the report within the hour.

  3. 03

    Review

    Each finding carries the registration record, the DNS answers and the certificate entries it rests on, plus the published rule that ranked it. You mark it once and the decision sticks to the name.

  4. 04

    Act

    Export the evidence, raise an alert against a saved query, or take it to the registrar. Most findings stop at the first step, which is the point of ordering them.

What one finding looks like

A single lookalike of example.com, and the order its evidence arrived in. Each line is one public record answering, on the day it answered. Nothing here required opening the site.

WhenWhat appearedSource
Day 0exmaple.com registered, registrar disclosed, registrant redactedRegistry RDAP
Day 1Certificate issued covering the name, before anything was reachableCertificate log
Day 3An address answers at 192.0.2.24DNS over HTTPS
Day 4Mail records published, so the name can send and receiveDNS over HTTPS
Day 4Priority raised to ElevatedPublished rule

The rule that raised it is the one on the methodology page: active infrastructure on a registration under a year old. What this sequence does not establish is intent. It says a name that resembles yours was registered, certificated and configured for mail inside four days, which is a name to look at first, not a finding of phishing.

What this does not do

It never loads a suspect website to read what is on it, so it cannot tell you what a page contains, and it never calls a domain malicious on similarity alone. A finding is a name to review under a published rule, not a finding of phishing. On Pro and above you can ask our team to report a finding you tagged malicious to its registrar or hosting network; a person sends it and records each step, and the checker itself never contacts the site.