Lookalike Domain Finder
See which impersonations of your domain someone has already bought.
Every well-known domain has a shadow: the near-misses a person types by accident, and the near-misses designed to be mistaken for the real thing. A dropped letter, a doubled one, a 1 in place of an l, a .co where the .com should be. Individually they look trivial. Collectively they are the raw material for phishing, for invoice fraud, and for quietly collecting mail intended for someone else.
Not every registered lookalike is hostile, and treating them all as findings is how this kind of report becomes noise. Large organisations defensively register their own typos, which is why a sweep of a major brand returns a hundred names — most of them held by the brand. The signal is in who holds them: a name sitting on a corporate brand-protection registrar is the system working, while the same name on a parking or aftermarket platform belongs to someone waiting to sell it or use it. This tool separates the two and puts the second group first.
What to do about a genuine squatter depends on what it is doing. A parked name with no mail and no site is worth monitoring rather than fighting. A name that has published a certificate, started resolving, or configured mail records has moved from speculation to preparation, and that is the point to escalate — through your registrar, a UDRP complaint, or simply by warning the people who would be targeted.
What this tool does
Ten permutation families
Omission, repetition, transposition, keyboard slips, insertion, hyphenation, homoglyphs, bitsquats, TLD swaps and the dot trick — the techniques squatters actually use.
Registration, not just guesses
Each candidate is checked for nameserver delegation, so the result is which names are genuinely taken rather than a list of things that could exist.
Separates squatters from your own defences
Nameservers on a brand-protection registrar mean the owner bought it defensively. Nameservers on a parking platform mean somebody else did. Those need very different responses.
Reports what it could not determine
A candidate whose lookup failed is counted as inconclusive, never quietly reported as available.
Frequently asked questions
What is typosquatting?
Registering a domain that is a near-miss for a real one — a dropped letter, a doubled letter, transposed characters, a different TLD — in order to catch traffic meant for the original. It is used for phishing, ad revenue, malware delivery, and for intercepting misaddressed email.
What is a homoglyph domain?
One that substitutes visually similar characters so the name reads correctly at a glance: a 1 for an l, a 0 for an o, or rn in place of m. These are the most dangerous variants because the difference survives a careful look at the address bar, which is why this tool rates them highest.
Why are so many lookalikes of big brands already registered?
Mostly because the brand registered them. Defensive registration is standard practice for large organisations, which is why a scan of a well-known domain returns dozens of hits. The nameservers tell you which is which — corporate brand-protection registrars indicate the owner, parking platforms indicate somebody else.
How is registration determined?
By querying for nameserver delegation. Every registered domain has nameservers, whether or not anything is served from it, so this catches names that are parked and dormant — which most squats are. A check for a website would miss them.
Why is WHOIS not used?
A sweep is hundreds of candidates and every registry rate-limits WHOIS and RDAP far below that. DNS answers the question that matters at this stage. Registrar and ownership detail is worth fetching for the handful that come back registered and suspicious, not for every candidate.
What does "inconclusive" mean?
The lookup did not return a definitive answer after retries, so the registration status is genuinely unknown. It is reported separately rather than being folded into "available", because a domain quietly assumed to be free is exactly the kind of wrong answer that makes a security report untrustworthy.
A lookalike of my domain is registered. What should I do?
Judge it by what it is doing. A parked name with no site and no mail records is worth monitoring. One that has obtained a certificate, started resolving, or configured MX records is being prepared for use — that is the point to act, via your registrar, a UDRP complaint, or by warning the people likely to be targeted.
Monitor it, don't just check it
One-off checks catch what is broken today. CertNotify watches your certificates, domains, DNS and code continuously and tells you before something breaks.