Know the day a new lookalike appears.
A check tells you what exists now. Monitoring tells you what changed, which is the part that needs a decision.
Why a snapshot is not enough
The useful fact about a lookalike is almost always its age.
Age is the strongest signal you have
Abusive use of a lookalike overwhelmingly happens close to registration. A name found two years late is an entry in a list; the same name found in its first week is a decision.
The first run is the hardest
An established brand's first check returns more findings than anyone expects, and most turn out to be its own. Without a way to settle those once, the list gets read once.
An alert on everything is an alert on nothing
A threshold nobody believes is worse than no threshold. What matters is being able to set one and see what it withheld.
What monitoring tracks
- Daily re-check
New registrations
Names that did not exist at the last run, with the creation date the registry discloses.
- Every 30 minutes
Certificates, within the hour
Logs are searched every thirty minutes for watched domains. A name seen for the first time queues a re-check at most once an hour.
- Change list
Changed evidence
An address appearing, mail records added, a nameserver moving. A finding that was dormant last week and is live this week is more urgent than a new one.
- Findings ledger
Findings that left
A name that stopped resolving is recorded as gone rather than silently dropped, so the record stays readable.
How it works
- 01
Check
Enter a domain. About 3,001 candidate names are generated across twenty pattern families, roughly 180 endings and forty hosting platforms, and every one is resolved over DNS.
- 02
Watch
Put the domain on a watchlist and it is re-checked daily, with certificate transparency logs searched every thirty minutes so a name being prepared reaches the report within the hour.
- 03
Review
Each finding carries the registration record, the DNS answers and the certificate entries it rests on, plus the published rule that ranked it. You mark it once and the decision sticks to the name.
- 04
Act
Export the evidence, raise an alert against a saved query, or take it to the registrar. Most findings stop at the first step, which is the point of ordering them.
What one morning's re-check reported
The whole output of a daily run on example.com. Not the 24 findings it holds, only what moved since yesterday, which is the part that needs a decision.
| Change | Name | What moved |
|---|---|---|
| New | secure-example.com | Registered 2 days ago, certificate already issued |
| New | exampl.com | Registered, delegated, nothing published yet |
| Priority up | exarnple.com | Review to Elevated: mail records appeared overnight |
| Evidence | example-login.com | Address changed to 198.51.100.7 |
| Gone | exampel.com | Stopped resolving, kept in the ledger with its dates |
Five lines instead of twenty-four. The two marked Owned last month did not reappear, because a decision sticks to the name rather than to the report it was made in. One alert was raised, for the priority change, because that was the only line above the threshold set for this domain.
What this does not do
Monitoring cannot stop a registration, and no service is consulted before one happens. What it changes is how long a name stays invisible to you. Daily re-checks and email alerts are on Pro; the base plan re-checks when you ask it to.