undoppel

Brand protection guide

How to Protect Your Brand From Domain Abuse and Typosquats

**Brand protection** against domain abuse means finding, monitoring, and shutting down the lookalike domains attackers register to impersonate you —…

How to Protect Your Brand From Domain Abuse and Typosquats

Brand protection against domain abuse means finding, monitoring, and shutting down the lookalike domains attackers register to impersonate you — before they steal customer logins, intercept payments, or send phishing email that looks like it came from you. The fastest way to do it is to map every plausible variation of your domain, watch for new registrations and certificates in real time, and enforce takedowns on the ones that are actively abusive. A scan at undoppel.io does the finding and monitoring part for you.

Attackers don't need to breach your servers to damage your brand. They just register a domain that looks close enough to yours, stand up a copy of your site or a login page, and let your own customers do the rest. Below is how these attacks work, how to spot them, and what actually stops them.

What domain abuse and typosquatting actually are

Typosquatting is registering a domain that relies on a predictable human error or visual trick to be mistaken for a legitimate one. Domain abuse is the broader category: any registration or DNS configuration that trades on your brand's identity to deceive, defraud, or harvest data.

These aren't one technique but a family of them. Understanding the variants is what lets you catch them, because each leaves a different fingerprint.

Why these attacks succeed

They exploit trust and inattention, not technical weakness. A customer who receives an email from `[email protected]` recognizes "example" and acts. On mobile, the address bar truncates the URL so the deceptive part never shows. Homoglyph domains defeat visual inspection completely — there is nothing to notice.

The infrastructure is cheap and fast. An attacker can register a lookalike, point its MX records at a mail server, and start sending convincing phishing within minutes. They can obtain a valid TLS certificate for free in seconds, so the padlock icon appears and the "not secure" warning never fires — the padlock proves encryption, not honesty. That combination (familiar-looking domain + working email + valid HTTPS) is enough to fool most people most of the time.

How to spot a lookalike domain targeting you

You're looking for domains that combine your brand with the signals of active abuse. A parked page is a nuisance; a domain with mail records and a login form is a live threat. Watch for:

  1. New registrations that permute your name — any of the variants above appearing in domain registration data, especially registered recently and anonymously.
  2. MX records on a lookalike — a typosquat configured to send and receive email is being weaponized for phishing or business email compromise, not just held for resale.
  3. Newly issued TLS certificates for domains containing your brand — every certificate issued gets logged in public certificate transparency (CT) logs, so a cert for example-verify.com is an early warning that someone is about to launch a site there.
  4. WHOIS and hosting signals — privacy-shielded registration, a registrant in a region you don't operate in, or hosting on infrastructure known for abuse.
  5. Content that mirrors yours — your logo, copy, or a cloned login page served from a domain you don't own.
  6. DNS pointing to live infrastructure — an A record resolving to a real server means the domain is set up to do something, now.

Checking all of this by hand across hundreds of permutations, refreshed daily, isn't realistic. This is exactly the monitoring undoppel.io runs for you — generating the permutations, checking DNS and WHOIS, and watching certificate transparency logs so a new lookalike surfaces the day it appears, not after a customer reports a scam.

How to protect your brand — the defensive playbook

Effective brand protection works in three layers: register what you can, monitor everything you can't, and enforce takedowns on what turns hostile.

1. Register your obvious variants defensively

You can't buy every possible domain, but you can remove the cheapest wins from the attacker's table.

Don't try to register your way to safety. Infinite permutations make that a losing budget line. Defensive registration handles the top of the funnel; monitoring handles the rest.

2. Harden your own domain against spoofing

Attackers spoof your exact domain in email unless you tell mail servers not to accept it.

These controls protect your exact domain. They do nothing about a lookalike domain the attacker owns outright — which is why monitoring is the layer that actually closes the gap.

3. Monitor continuously and enforce takedowns

New lookalikes get registered constantly, so a one-time audit ages out within weeks. Continuous monitoring flags each new permutation as it appears, along with the abuse signals — MX records, live DNS, a fresh TLS certificate, cloned content — that tell you whether it's dormant or dangerous.

When you find a live threat, act on the fastest available lever:

Keep evidence for every case: screenshots, the resolving IP, WHOIS at time of discovery, and the certificate record. Documented, time-stamped proof is what makes a takedown move in hours instead of weeks.

Find the lookalikes that already exist

Most brands already have typosquats and combosquat domains registered against them — they just haven't found them yet. Run a free scan at undoppel.io to see which lookalike and typosquat domains targeting your brand are live right now, which ones have mail records or certificates set up to phish your customers, and which need a takedown first. Start with your primary domain and let the scan surface the full map before an attacker uses it.

Is your brand being impersonated?

Run a free instant scan for typosquats and lookalike domains targeting your brand.

Run a free brand scan →