undoppel

Brand protection guide

How to Detect Brand Impersonation and Lookalike Domains

Detect brand impersonation by watching for domains that mimic your name through misspellings, character swaps, or added words, and by monitoring newly…

How to Detect Brand Impersonation and Lookalike Domains

Detect brand impersonation by watching for domains that mimic your name through misspellings, character swaps, or added words, and by monitoring newly registered domains, DNS records, TLS certificates, and certificate transparency logs for anything resembling your brand. The fastest way to find them is an automated scan that generates every plausible lookalike variation and checks which ones are actually registered and live — which is exactly what a scan at undoppel.io does for you.

Brand impersonation is when an attacker copies your name, logo, domain, or visual identity to trick your customers, employees, or partners into trusting a fraudulent site, email, or account. Lookalike domains are the infrastructure that makes it work: a convincing web address is what turns a generic phishing email into one people actually click.

What brand impersonation looks like in practice

Impersonation isn't one attack — it's a category. The common forms share a goal: borrow your credibility to steal money, credentials, or data.

The web address is the linchpin. A message from `[email protected]` looks legitimate at a glance, and that glance is all the attacker needs.

The techniques attackers use to build lookalike domains

Understanding how lookalikes are constructed tells you what to look for. Most fall into a handful of predictable patterns — which is also why they can be generated and detected systematically.

Character substitution and misspellings

The simplest typosquatting swaps, drops, or doubles letters: `exemple.com`, `exampple.com`, `exampe.com`. Others substitute visually similar characters — the number `1` for a lowercase `l`, `0` for `o`, `rn` for `m` (so `example.com` becomes `exarnple.com`). These exploit fast reading and small screens.

Homoglyphs and internationalized domains

Homoglyph attacks use characters from other alphabets that look identical to Latin letters. A Cyrillic "а" renders the same as a Latin "a" but is a completely different character, producing an IDN (internationalized domain name) that looks exactly like your brand while pointing somewhere else. These are among the hardest lookalikes to catch by eye.

TLD swaps

Attackers keep your exact name but change the extension: your `.com` becomes `.net`, `.org`, `.co`, `.shop`, or a country-code domain. Customers who trust your name rarely verify the ending.

Combosquatting

Combosquatting appends or prepends real words: `example-support.com`, `login-example.com`, `example-secure.net`, `myexample.com`. Because your actual brand name is present and spelled correctly, these read as legitimate and evade simple misspelling filters.

Subdomain and path tricks

The real deception often hides in structure: `example.com.verify-account.net` puts your brand in the subdomain of a domain the attacker controls. Everything before the final `.net` is under their control, but a hurried reader sees "example.com" first and trusts it.

The signals that prove a lookalike is a real threat

A registered lookalike domain isn't automatically dangerous — plenty sit dormant. These signals separate a live threat from harmless noise:

  1. Recent registration — a domain registered days ago that mimics your brand is a strong indicator of intent. WHOIS registration dates reveal this.
  2. MX (mail exchange) records configured — if a lookalike domain has mail servers set up, it can send email that appears to come from your brand. This is the clearest sign of planned phishing or invoice fraud.
  3. An active TLS certificate — a lookalike with a valid HTTPS certificate is preparing (or already running) a site that shows the reassuring padlock. Certificate issuance is logged publicly in certificate transparency (CT) logs, so new certs for lookalike names surface almost immediately.
  4. Live content that copies your site — cloned pages, your logo, or a login form pointing at your brand.
  5. Privacy-shielded or mismatched WHOIS — hidden registrant details on a brand-adjacent domain, or a registrant in an unexpected country, raises the risk profile.
  6. DNS pointing to hosting — A records resolving to a live server mean the domain is set up to serve something, not just parked.

No single signal is proof, but MX records plus a fresh registration plus a TLS certificate is a near-certain sign someone is about to impersonate you.

How to detect brand impersonation systematically

Manually imagining every misspelling of your name and checking each one is impossible — the permutation space runs into thousands of variations across character swaps, homoglyphs, combosquats, and TLDs. Detection has to be generated and monitored automatically.

A proper brand-impersonation scan works in stages:

  1. Generate permutations — algorithmically produce every plausible lookalike: misspellings, homoglyphs/IDN variants, TLD swaps, combosquatting patterns, and subdomain tricks derived from your brand name and domain.
  2. Resolve and check registration — determine which of those thousands of variants are actually registered, and pull WHOIS data for registration dates and registrant details.
  3. Inspect DNS records — check for A records (a live site), MX records (mail capability), and other DNS entries that reveal what the domain is set up to do.
  4. Watch certificate transparency logs — surface newly issued TLS certificates for lookalike names the moment they're created, catching threats before a phishing page ever goes live.
  5. Prioritize by risk — combine these signals so the domains with mail servers, fresh registrations, and active certificates rise to the top instead of getting lost in dormant noise.

This is the work Undoppel does for you at undoppel.io — you enter your brand, and the scan generates the permutations, checks registration and DNS, watches certificate transparency logs, and flags which lookalikes are live threats rather than harmless parked names.

What to do when you find a lookalike domain

Detection is only useful if it drives action. Once a threatening lookalike surfaces:

Defensive registrations that shrink the attack surface

You can't register every possible variation, but a few defensive moves close the highest-value gaps:

These reduce what attackers can grab cheaply — but they don't stop homoglyphs, obscure TLDs, or subdomain tricks, which is why monitoring remains the backbone of any brand-protection program.

The single most useful thing you can do right now is find out which lookalikes already exist. Run a free brand scan at undoppel.io to see the registered typosquats, homoglyph domains, and combosquats targeting your name — along with which ones have mail servers, live sites, and certificates ready to impersonate you.

Is your brand being impersonated?

Run a free instant scan for typosquats and lookalike domains targeting your brand.

Run a free brand scan →