DomainGuard · lookalike watch

They register the name months before they use it.

A domain one letter off yours is bought, parked, and left alone until there is a payment worth redirecting. By the time the invoice goes out it has a mail server and a page that looks like yours. Monitoring is about the months in between, when the registration exists and nobody has looked.

Already know what exists today? The free lookalike domain check needs no account. This page is about what changes after that.

Three ways a name becomes visible

One vector is not monitoring. It is a snapshot.

Each of these catches a registration at a different moment in its life, and the earliest one is the one a single lookup cannot use.

  1. Vector 01

    Permutations, resolved against DNS

    Around twenty generation algorithms — wrong ending, your name plus a word, dropped letters, doubled letters, swapped neighbors on the keyboard, hyphens added and removed, homoglyphs from other alphabets — each candidate checked for a real delegation. Registered means somebody bought it.

    Fires once the domain is delegated.

  2. Vector 02

    Certificate transparency

    Every publicly trusted certificate is logged. Searching those logs finds names that were never in the permutation list, including the ones somebody thought up rather than typo'd into.

    Fires once somebody requests a certificate.

  3. Vector 03

    The daily new-registration feed

    The other two both wait for the attacker to leave a trace. A domain registered this morning has neither a delegation nor a certificate. Matching brand tokens against the daily list of newly registered names closes the gap between registration and first use, which is the window where telling you is worth the most.

    Fires the day it is registered. Coverage is most common endings, once a day, so it is a head start rather than a census.

The part that decides whether you use it twice

Finding four hundred domains is easy. Saying which three matter is the product.

A generator that prints every permutation is a solved problem and a useless one. These are the rules the risk model is built on.

Capability outranks resemblance

A domain one letter off yours that resolves nowhere is a curiosity. A domain three letters off that can receive mail is an active business-email-compromise risk. Mail capability is weighted above every measure of string similarity, and string distance is not scored on its own at all.

Copied content outranks capability

The one signal that beats being able to send mail is evidence of intent: a homepage that copies yours, or a favicon that matches it. That is not a coincidence anyone has to argue about.

Subtractions are load-bearing

If you already bought six defensive variants, a tool that reports six threats is noise and you would be right to say so. Negative signals exist so the first run is believable — parked, unresolving and obviously-yours registrations score down, not up.

Not observed is never scored as safe

Every signal can be null, and null means the lookup did not answer, not that the record is absent. A rate-limited resolver must not quietly downgrade every finding at once.

The four bands

Benign
Registered, but nothing about it points at you. Usually somebody else's real business, or a variant you own.
Watch
Worth knowing about. Registered and resembling you, with no capability behind it yet.
Suspicious
Capability has appeared: it resolves, or it can receive mail, or a certificate was issued for it.
Active threat
Capability plus intent. Mail records and a page dressed as yours is the combination that precedes an invoice.

Your judgement, kept

Three verdicts, not three words for dismiss.

A finding you have already decided about should not come back next month wearing the same face. What it should do depends on which kind of decision you made.

This one is ours
A defensive registration you already hold. It stops being scored and stops being alerted, and it stays visible so a later change on it is still noticed.
Unrelated
Somebody else's legitimate domain that happens to look close. Marked once, and it does not come back every scan.
We know
Real, hostile, and already being dealt with. Acknowledged rather than dismissed, because the filing is still open.

Changes raise events with an acknowledge and resolve lifecycle, so a domain that goes from parked to mail-capable is a new thing to look at rather than a row that silently changes color. Looking at your own domain's history is never plan-gated; the paid gate sits on the watching, not on the reading.

The boundary

Every domain in this list belongs to somebody else.

That fact sets the rules. Registry data, DNS and certificate logs are public records and reading them touches registries rather than the other party. One request for the homepage is the furthest this feature goes, and it is gated on you having proved you own the domain being impersonated.

There is no port scan, no path enumeration and no template scanner pointed at a lookalike, and there never will be. A domain we report is a domain somebody registered, which is a fact. Whether they registered it to defraud your customers is a judgement, and you get the evidence rather than the verdict.

Straight answers

Questions about impersonation monitoring.

How is this different from the free lookalike check?

The free tool at /lookalike-domain-check is a single lookup for a single domain, with no account, and it answers the question “what exists right now”. Monitoring answers a different question: “what appeared since last time”. It runs on a schedule, keeps the previous result to compare against, raises an event when something changes, and adds the new-registration feed, which a one-off check cannot use because there is nothing to compare a first run against.

Do you scan the lookalike domain itself?

No, and this is a hard line in the code rather than a policy in a document. DNS, registry records and certificate transparency are public and reading them touches registries, not the other party's server. There is one request to the lookalike's homepage, which is exactly what a browser does when a person types the name, and it is gated on you having proved ownership of the domain being impersonated. No port scan, no path enumeration, no template scanner, ever.

Can you get the domain taken down?

No. Removing a domain means a complaint to its registrar with evidence attached, or a UDRP filing. DomainGuard assembles the evidence pack — registry data, DNS and mail records, certificate history, and the content comparison — and that pack is deliberately not behind the paywall. The paid line in this feature is the watching, and somebody who has found a domain being used against them should not hit a payment screen between the finding and the filing.

What does it cost?

Running a lookalike scan by hand on a domain in your own account is not plan-gated: any signed-in account can do it. The continuous watch — scheduled re-scans, the new-registration feed, and alerts when something changes — starts on the Starter plan at $6.99 a month. Turning a watch off is always allowed on any plan, so a downgrade never leaves a switch stuck on.

Will this find every lookalike?

No, and any tool claiming otherwise is describing an ambition. The permutation engine is ranked rather than exhaustive because every candidate costs a lookup, so the algorithms that historically produce registered domains run first and a budget cuts the tail. The new-registration feed covers most common endings once a day, not every ending in real time. The honest claim is broad coverage of the shapes attacks are actually built from.

See what is already out there

Run the check once. Then decide whether you want it watched.

The one-off check needs no account. The continuous watch starts at $6.99 a month, and the iPhone app is free to join on TestFlight while it is in beta.