Find the domains
pretending to be you.
Before a convincing phishing email reaches your customers, somebody registers the domain it will come from. ClickScan sweeps thousands of variations of your name, works out which of them can actually do something, and tells you what was examined as well as what was found.
ClickScan is not open to the public yet. Leave us your details and we’ll tell you the day it opens.
What impersonation actually looks like
Rarely a clone of your website. Almost always a domain name close enough to yours that nobody reads it twice.
Typosquatting
Your name with a character wrong: a letter dropped, two swapped, a neighbouring key hit instead. These catch people who mistype the address and people who skim an email address rather than read it.
Look-alike characters
An i replaced with an l, an o with a zero, or a Latin letter replaced with an identical-looking one from another alphabet. The last kind is an IDN homoglyph, and it can be indistinguishable in most fonts.
Compound names
Your name joined to a word that makes the domain look official: yourbrand-login, yourbrand-support, secure-yourbrand. Nothing is misspelled, which is exactly why they work.
Another ending
The same name under a different suffix. Your .com is registered by you; the same name under a country ending or one of the hundreds of newer endings is not.
Your name as a subdomain
yourbrand.some-other-site.example — the visible part of the address is yours, the domain it actually belongs to is not. Nobody has to register anything close to your name at all.
Combinations of the above
A mistyped name under a different ending, or two look-alike substitutions at once. These are the ones a single-pattern search misses, and the deep sweep is where they are found.
Existing is not the point. Capability is.
Most domains that resemble a well-known name are parked, for sale, or another company’s own defensive registration. A tool that lists all of them as threats is a tool people stop opening.
Each one gets a verdict, not a row in a list
Every candidate that exists is resolved and classified from what it can actually do: whether it serves a website, whether it has mail servers configured, whose nameservers it sits on, and when it first appeared in the public certificate logs. Yours, another company’s brand protection, parked, registered-and-idle, serving a site, mail-capable, or all of the above at once — with the worst one driving the grade.
Your own domain is the first row of the table, so “these nameservers are the same as yours” is a comparison you can make rather than a verdict you have to accept.
A certificate is the signal that it is being prepared
A domain registered years ago whose first certificate was issued last week is not old, whatever its registration date says — it is a campaign being set up. We read that from the public Certificate Transparency logs, which answer for every domain ending, including the ones that publish no registration data at all.
The report says what was examined
“We found no lookalike domains” is worth nothing on its own — a sweep where half the answers never came back reads exactly like a clean one. So every variation we built is accounted for: found, confirmed absent, unanswered, not reached, skipped, or discarded because the zone answers for every possible name.
If the sweep could not be completed and found nothing, it is graded not applicable and the credits are returned, rather than being reported as good news.

And then what?
A list of impersonating domains is only useful if there is something to do with it.
Register the ones worth having
The sweep also reports the variations nobody has taken yet — only the ones we confirmed are genuinely free, and only the ones you could actually buy. It is the standard defensive move, and it is much cheaper before somebody else makes it.
Push them into your own tools
Findings download as a STIX 2.1 bundle or as YARA rules, for the whole scan or one domain at a time. Only what is worth acting on is exported — a parked domain or another company’s brand protection is not written into a file that feeds a blocklist.
Correct us when we get one wrong
We decide whether a similar domain is yours from your own DNS, which catches a defensive registration on your nameservers and misses a subsidiary registered elsewhere. Tell us it is yours and we stop treating it as an impersonation — on that report and every later one. That corrects the check rather than hiding what it said, so it moves the grade; taking it back moves the grade back.
Watch it, rather than checking it once
Run it daily, weekly or monthly at a discount, and hear from us only when something moves — a new registration, or a domain that has just gained mail servers. If we widen the list of names we sweep for, the comparison says so instead of reporting the names it stopped looking for as fixed.
What this is not
Worth saying plainly, because the category is full of tools that imply more than they do.
We never touch the lookalike
Everything is read from public DNS and public certificate logs. We do not connect to the impersonating domain, load its site, or send it anything.
Not a takedown service
We find them, evidence them and export them. Filing with a registrar, a host or a brand-protection lawyer is a separate job, and we would rather say so than let you assume it is included.
Not trademark monitoring
This watches the domain name system. Marketplace listings, social handles and app stores are a different problem and we do not claim to cover them.
Questions
What is brand impersonation, in domain terms?
Somebody registering a domain close enough to yours that a reader does not notice the difference — a mistyped version of your name, your name joined to a word like “login”, the same name under a different ending, or a character swapped for one that looks identical. It is the first step in most phishing aimed at your customers or your staff.
How is this different from just searching for similar domains?
Finding them is the easy half. Most domains resembling a known name are parked, for sale, or another company’s own defensive registration, so a flat list trains you to ignore it. Every candidate here is resolved and classified by what it can actually do — serve a website, receive email, sit on your own nameservers — and the report leads with how many are worth acting on rather than how many exist.
Do you connect to the impersonating domain?
No. Everything is read from public DNS and the public Certificate Transparency logs. We never load the lookalike’s site or send it anything.
Will it find IDN homoglyphs?
Yes, and it also tells you whether a browser will actually render one. Every major browser refuses to display a domain that mixes alphabets and shows the raw xn-- form instead, so a mixed-script lookalike is a weaker threat than it appears — while one written entirely in another alphabet is the dangerous kind, because it renders as written.
Can you take an impersonating domain down?
No — we find them, evidence them and export them. Filing with a registrar or a host is a separate job, and we would rather say so than let you assume it is included.
What if one of the domains it finds is mine?
Tell us, and we stop treating it as an impersonation on that report and every later one. We decide ownership from your DNS, which catches a defensive registration on your own nameservers and misses a subsidiary registered elsewhere. Because that corrects the check rather than hiding what it said, it does move the grade — and withdrawing it moves the grade back.
