Capability · Enterprise

Someone registered your brand
with one letter changed.

Lookalike domains are registered long before they are used. GuardianGaze finds them, establishes who is behind them, and pursues the takedown, with the evidence package attached and the finding tracked until the domain is gone.

Takedown workflow included in Brand Protection.

The workflow

Detect, verify, file, track

The hard part is not spotting a lookalike domain. It is proving who owns it and getting somebody with authority to act.

01

Detect

Typosquat and lookalike-TLD registrations against your brand are found continuously, not when a customer reports one.

02

Verify

WHOIS and abuse intelligence establish who registered it and through which provider. Indicators are analyst-verified before anyone acts.

03

File

A takedown is raised through the registrar or hosting provider's abuse channel, with the evidence package attached.

04

Track

The finding stays open with an SLA until the domain is down, and the outcome is recorded in the audit trail.

What we look for

  • Typosquat registrations, character swaps, insertions and omissions
  • Lookalike TLDs carrying your exact brand term
  • Hostile WHOIS patterns and bulk-registration signals
  • Abuse intelligence on the registrar and hosting provider
  • Impersonation surfacing in brand-mention intelligence

What we hand over

  • The registration record and the evidence that flagged it
  • Analyst verification before the finding is raised
  • The abuse channel used and the filing itself
  • An SLA and open status until resolution
  • The outcome recorded in the activity audit trail
Brand protection findings with registration evidence and status

Each lookalike domain tracked as a finding, with evidence and status

Questions

Common questions

Is takedown included or an add-on?

Included. If we find a typosquat registered against your brand, pursuing the takedown is part of the Brand Protection module rather than a separately priced service.

How do you find lookalike domains?

Continuous typosquat and lookalike-TLD detection against your registered brand terms, backed by WHOIS and abuse intelligence to establish ownership and the responsible provider.

Can you guarantee a domain comes down?

No, and nobody honestly can, the decision sits with the registrar or hosting provider. What we commit to is detection, a verified evidence package, the filing itself, and tracking the finding to closure with an SLA.

What if the domain is registered but not yet weaponised?

It is still reported. A parked lookalike domain is usually the preparation stage, and it is far cheaper to have it removed before it hosts a login page carrying your logo.

The window

Registration is preparation, not the attack

A lookalike domain is almost never used the day it is registered. It sits idle while infrastructure is assembled (hosting configured, a certificate issued, a copy of your login page built, mail records added) and only then does the campaign run.

That gap is the whole opportunity. A takedown filed against an idle domain is a straightforward abuse report. A takedown filed while a campaign is live is a race against how many of your customers submit credentials in the meantime, and the reputational damage is already occurring while the registrar works through their queue.

Certificate transparency is the most reliable early signal we have. Anyone building a convincing phishing page needs TLS, and issuing a certificate writes a public log entry, frequently days before the first message is sent.

Verification

Why every candidate is checked before it is filed

Not every similar domain is hostile. Regional partners, resellers, affiliates, defensive registrations made by your own marketing team years ago, and plain coincidence all produce matches that look alarming in a list.

Filing indiscriminately has a real cost, and it is not just wasted effort. Registrars and hosting providers triage abuse reports by submitter reliability, so a requester with a poor accuracy record gets deprioritised, which means the report that genuinely matters sits behind the ones that did not.

So candidates are analyst-verified before they become takedown requests, with the supporting evidence assembled: registration data, hosting, certificate issuance, any content being served, and mail configuration. A lookalike domain with MX records configured is preparing to send mail, and that raises priority sharply.

To closure

Submission is not resolution

The most common failure in domain takedown is treating the submitted report as the finished work. Registrars respond at wildly different speeds, to differently constructed evidence, under different abuse policies and in different jurisdictions. A proportion of first requests go nowhere and need escalation, re-filing with different evidence, or a route through the hosting provider rather than the registrar.

Tracking to closure means the case stays open until the domain is suspended, transferred or demonstrably dead, not until the email was sent. That is the difference between a takedown capability and a takedown intention.

It is included rather than sold as a separate service, which is a deliberate choice: detection you cannot act on is an anxiety generator, and charging separately for the action turns every finding into an upsell conversation at the worst moment.

Find out what has been registered against you

Brand protection is assessed alongside your infrastructure, so the lookalike domain and the exposed host arrive in the same report.

Free for your own organisation.