Skip to content

← Web security

Lookalike / typosquat domain finder

Attackers register look-alikes of your domain — one-character typos, homoglyphs, hyphenations, alternate TLDs — to phish your staff and customers. We generate the common permutations, DNS-resolve each, and show you which ones already exist.

Find lookalikes of your domain

We generate common typo / lookalike permutations of your domain and DNS-resolve each one to see which are already registered. DNS-only — no HTTP requests. Takes a few seconds.

How it works: We take the registrable label of your domain and apply the classic dnstwist-style algorithms — character omission, adjacent-key insertion / replacement, transposition, repetition, ASCII homoglyph swaps (0/o, rn/m, vv/w, …), hyphenation, small bit-flips, and common TLD swaps (.com/.net/.org/.co/.io). Each candidate is resolved server-side against DNS (A/AAAA, then CNAME, then NS). We make no HTTP requests— DNS only — so it's fast and never touches the suspicious sites.

A candidate that resolves or is delegated (has name servers) is registered — a potential phishing vector worth verifying. It is not proof of malice: it may be you, a partner, or a parking company. We report registration, never intent. The generated set is bounded and covers the common patterns — it is not exhaustive, and IDN / punycode homoglyph attacks are out of scope in this version.

Want your domain (and its look-alikes) watched continuously, with an alert the moment a new imitator gets registered? Add it to continuous monitoring, and pair it with phishing-awareness training so your team can spot the ones that slip through.