Help center
Impostor domains (Lookalike Watch)
Finding domains registered to look like yours, how risk is scored, the nightly watch on paid plans, verdicts, change events and the evidence pack for a filing.
Updated · 4 articles
Somebody registers a name one letter off yours, points a mail server at it, and sends your customers an invoice with new bank details. Lookalike Watch finds those names before the invoice goes out, tells you which ones can already receive mail, and keeps checking.
Articles
- The lookalike check - how variations are generated, how many are checked, and why "nothing found" always comes with a count.
- Lookalike watch and alerts - the nightly re-check on paid plans, candidate budgets per plan, and the alert switches.
- Risk bands and signals - benign, watch, suspicious and active threat; MX, certificates, homepage title and favicon, and the new-registration feed.
- Verdicts, change events and the evidence pack - ours, unrelated or known; appeared, gained mail, escalated; and the pack for a registrar complaint.
Where
- Web: a domain's Impostor domains module; the public tool at nhmohio.com/lookalike-domain-check.
- iOS: the Impostor domains module on a domain's page, with Needs review and Watching groups.
- API/MCP:
POST /api/lookalike-check(public),GET /api/domains/:id/lookalikes,POST /api/domains/:id/lookalike-scan,PUT …/lookalike-watch,PUT …/lookalike-verdict,GET …/lookalike-events,GET …/lookalike-evidence; toolslist_lookalikes,run_lookalike_scan,set_lookalike_watch,set_lookalike_verdict,get_lookalike_events,act_on_lookalike_event,get_lookalike_evidence,get_lookalike_alert_settings,update_lookalike_alert_settings.
What DomainGuard does not do here
It does not take a domain down. A lookalike is a registrar abuse complaint or a UDRP filing; DomainGuard assembles the evidence and you file.
How the pieces fit
- The check generates variations of your name and finds the ones that exist. Free, on every plan, and public on the website.
- Each hit is scored from what it can do (receive mail, serve HTTPS, resolve) and what has been done with it (copied title, copied favicon), never from how similar it looks.
- The watch re-runs the check weekly or daily and raises an alert only when something changes.
- A verdict is your word on what a hit is, and it stops the noise without hiding an escalation.
- The evidence pack is what you hand to the registrar or file with a complaint.
Common questions
Is this the same as DMARC? No. DMARC stops someone sending mail as yourdomain.com. A lookalike is yourdomain.co or your-domain.com, which DMARC cannot touch; the only defences are noticing it early and filing.
Does the check touch the impostor's server? DNS, RDAP and certificate log reads do not. The homepage and favicon comparison does, and it runs only on a cleared account.
In reading order
Articles in Impostor domains
- The lookalike checkHow variations are generated and ranked, how many are checked on each plan, what is read about each registered one, and why the result states its coverage.Updated
- Lookalike watch and alertsKeeping the check running: weekly on Starter, daily on Pro and Enterprise, with an alert when a lookalike appears, gains mail or escalates. Off is always free.Updated
- Risk bands and signalsHow a lookalike is scored: the four bands, the signals that raise or lower the score (mail, certificate, age, copied title and favicon), and what is not scored.Updated
- Verdicts, change events and the evidence packTell DomainGuard what a lookalike is (ours, unrelated or known), read the change history for each, and assemble the pack for an abuse report or takedown filing.Updated
Still stuck?
Ask the people who run the scanner.
Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.
