Look-alike domains: which ones matter

Look-alike domains: which ones matter

For any name worth impersonating, thousands of variations resemble it. Almost all are unregistered, parked, or owned by somebody with no interest in you at all.

A tool that hands you nine hundred "threats" has told you nothing. The useful question is which of them can do something: send email that looks like yours, serve a website, or hold a certificate.

How the candidates are built

The monitor generates variations the way somebody trying to fool your customers would:

  • Look-alike characters — the Cyrillic а that renders identically to a Latin one, rn reading as m, 1 for l.
  • Typos — a transposed pair, a doubled letter, a missing one, a key struck next to the right one.
  • Compound names — your brand plus -login, -support, -secure, -billing, the words that make a phishing link look like infrastructure.
  • Alternative endings — the same name under a different domain ending.

The deep sweep widens all of that: every country ending rather than the common ones, two look-alike substitutions at once, and every single-character typo.

How each candidate gets a verdict

Every generated name is resolved against DNS, mail servers, certificate transparency logs and live content. Each candidate lands in exactly one verdict — registered or not, resolving or not, able to receive mail or not, serving a site or not.

That last group is what you act on. A registered domain that resolves nowhere is a note. One with an MX record is a domain that can send email that looks like yours.

A Brand Impersonation deep sweep: five look-alike domains registered, two live, one able to receive email — with a coverage account showing 11,453 variations built and 11,447 checked

The part most tools leave out

Look at the bottom of that report: 11,453 variations built, 11,447 checked, in 335 seconds — and then an explicit account of the difference. Some could not be looked up, which is not the same as "not registered". Some were skipped because they are on the blocked-target list. Some answers were discarded because the domain ending answers for every possible name, so the answer proved nothing.

Those six unchecked names are the difference between "nothing found" as a claim and as something you can verify. A coverage figure that silently rounds to 100% is the one number in a security report you should never trust.

Getting the findings out

Findings export as STIX 2.1 or YARA, so they can feed a threat intelligence platform or a detection rule rather than living in a PDF.

What this is not

No takedowns, no trademark monitoring, and ClickScan never connects to the look-alike as a victim would. It establishes what exists and what it is capable of. Acting on it — registrar complaints, legal routes — is your call.

The check costs five credits, the deep sweep eight, and neither needs proof of ownership. Start at app.clickscan.ai.

← Back to blog