Module · Enterprise

Brand protection,
before they finish using it.

Continuous monitoring of newly-registered lookalike domains, typosquats, dark-web mentions and social impersonation. If we find a typosquat trading on your name, takedown is included in the service.

Takedown workflow included, not sold as an add-on.

At a glance

Brand Protection at a glance

Coverage

What we observe

Lookalike and typosquat registrations, dark-web credential mentions, impersonation accounts and phishing infrastructure aimed at your brand.

Scoring

How it's scored

Each observation maps to a published, versioned rubric. Click any score component to see the evidence behind it.

Action

What happens next

Confirmed impersonation goes to takedown. You get the case reference and the outcome, not just an alert.

What we observe

  • Typosquat and lookalike-TLD registrations against your brand terms
  • WHOIS and abuse intelligence establishing who registered them
  • Corporate credentials exposed in breach data, matched to your domains
  • AI brand-mention intelligence across web and social, with sentiment
  • Impersonation attempts and early crisis signals

What arrives on a finding

  • Analyst verification before an indicator is raised
  • Severity with the evidence that produced it
  • Takedown filed through the registrar or host abuse channel
  • SLA and open status tracked to resolution
  • Outcome recorded in the activity audit trail
Worked example

Anatomy of a finding

FindingLookalike domain registered against your brand on an alternate TLD
EvidenceThe registration record, registrar and WHOIS pattern that flagged it
Why it mattersLookalikes are registered before they are weaponised; this is the preparation stage
Who it affectsCustomers and staff who would not read the address bar closely
RemediationTakedown filed with the evidence package, tracked until the domain is gone
Brand protection dashboard showing lookalike domain monitoring

Live monitoring of typosquats and lookalike domains

What it watches

Impersonation infrastructure, before the campaign runs

Brand protection here means the infrastructure attackers build to impersonate an organisation, rather than trademark enforcement or social listening. Lookalike domain registrations, homograph domains using visually similar characters, alternative TLDs of a brand name, and certificates issued for any of them.

The timing is the point. Registration is preparation, not the attack, a lookalike domain typically sits idle for days or weeks before a phishing campaign runs from it. Watching registrations gives a window in which the response is cheap, and a takedown before a campaign is a materially different exercise from a takedown during one.

Certificate transparency is the most reliable early signal. An attacker preparing a convincing phishing site needs TLS, and issuing a certificate writes a public log entry. That entry frequently appears before any mail is sent.

Why it is not just a phishing problem

Impersonation reaches customers, staff and suppliers at once

The obvious victim is a customer who enters credentials on a convincing copy of your login page. The less obvious ones are more expensive.

Suppliers receiving payment change requests from a domain that resembles yours is business email compromise pointed at your supply chain, and the loss lands on relationships you depend on. Staff receiving internal-looking mail from a lookalike domain sidesteps every control you built on your real domain, perfect DMARC enforcement does nothing about a different domain that merely looks like yours.

And there is a reputational tail that outlasts the incident. Customers who were defrauded through a site bearing your brand rarely distinguish carefully between you and the attacker, and the support and remediation cost usually exceeds the direct fraud.

Acting on it

Verification first, then takedown

Not every similar domain is hostile. Resellers, regional partners, affiliates, defensive registrations by your own marketing team, and genuine coincidence all produce matches. Sending takedown requests indiscriminately wastes registrar goodwill you will need later, and repeat submitters with poor accuracy get deprioritised.

So findings are analyst-verified before they become takedown candidates, with the evidence attached: registration data, hosting, certificate issuance, content if any is being served, and mail configuration: a lookalike domain with MX records configured is preparing to send, which raises priority sharply.

Takedown is then tracked to closure rather than handed off. Registrars and hosting providers respond at very different speeds and to differently constructed evidence, and a request that is filed and forgotten is not a control. This is included rather than sold as a separate service.

Questions

Common questions

How early can you detect a lookalike domain?

Often at registration, and usually at certificate issuance: an attacker building a convincing phishing site needs TLS, and issuing a certificate writes a public transparency log entry. That frequently precedes any mail being sent.

Does good DMARC protect us from lookalike domains?

No. A domain with a substituted character is a different domain and can publish its own perfect authentication records. Mail authentication and impersonation monitoring cover different halves of the same problem.

Are all similar domains hostile?

No, resellers, regional partners, affiliates, your own defensive registrations and plain coincidence all produce matches. Findings are analyst-verified before they become takedown candidates, because indiscriminate requests waste registrar goodwill you will need later.

What raises the priority of a lookalike domain?

MX records configured, a certificate issued, or content being served. A domain set up to send mail is preparing to send mail.

Is takedown included or an add-on?

Included. Takedown is tracked to closure rather than handed off, because a request that is filed and forgotten is not a control.

How long does a takedown take?

It varies considerably by registrar and hosting provider, and by how the evidence is constructed. That variance is the reason the workflow tracks to closure rather than treating submission as completion.

Related

Where this connects

Domain takedown →

The takedown workflow, tracked from evidence to closure.

Domain security module →

Mail authentication on your own domains.

Dark web monitoring →

Credential exposure and crisis signals attributable to your brand.

Rate your own brand protection first

See what attackers and insurers see. Free for your own organisation.