Help center

Impostor domains (Lookalike Watch)

Finding domains registered to look like yours, how risk is scored, the nightly watch on paid plans, verdicts, change events and the evidence pack for a filing.

Updated · 4 articles

Somebody registers a name one letter off yours, points a mail server at it, and sends your customers an invoice with new bank details. Lookalike Watch finds those names before the invoice goes out, tells you which ones can already receive mail, and keeps checking.

Articles

Where

  • Web: a domain's Impostor domains module; the public tool at nhmohio.com/lookalike-domain-check.
  • iOS: the Impostor domains module on a domain's page, with Needs review and Watching groups.
  • API/MCP: POST /api/lookalike-check (public), GET /api/domains/:id/lookalikes, POST /api/domains/:id/lookalike-scan, PUT …/lookalike-watch, PUT …/lookalike-verdict, GET …/lookalike-events, GET …/lookalike-evidence; tools list_lookalikes, run_lookalike_scan, set_lookalike_watch, set_lookalike_verdict, get_lookalike_events, act_on_lookalike_event, get_lookalike_evidence, get_lookalike_alert_settings, update_lookalike_alert_settings.

What DomainGuard does not do here

It does not take a domain down. A lookalike is a registrar abuse complaint or a UDRP filing; DomainGuard assembles the evidence and you file.

How the pieces fit

  1. The check generates variations of your name and finds the ones that exist. Free, on every plan, and public on the website.
  2. Each hit is scored from what it can do (receive mail, serve HTTPS, resolve) and what has been done with it (copied title, copied favicon), never from how similar it looks.
  3. The watch re-runs the check weekly or daily and raises an alert only when something changes.
  4. A verdict is your word on what a hit is, and it stops the noise without hiding an escalation.
  5. The evidence pack is what you hand to the registrar or file with a complaint.

Common questions

Is this the same as DMARC? No. DMARC stops someone sending mail as yourdomain.com. A lookalike is yourdomain.co or your-domain.com, which DMARC cannot touch; the only defences are noticing it early and filing.

Does the check touch the impostor's server? DNS, RDAP and certificate log reads do not. The homepage and favicon comparison does, and it runs only on a cleared account.

Still stuck?

Ask the people who run the scanner.

Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.