/ Free Tools — Lookalike Domain Scanner
The domains built to wear your name.
Generate the typosquat, homoglyph, and Unicode-homograph domains an attacker would use to impersonate you — then check live which are already registered and which have mail servers, meaning they're armed to phish as you. A risk map lights up each variant. In your browser, nothing sent but DNS.
Generates lookalike variants and checks each for registration and mail servers live over DNS-over-HTTPS. Only candidate domain names leave your browser.
/ What this does
Phishing that wears your brand almost always starts with a lookalike domain — a typo, a character swap, a near-miss TLD, or a Unicode twin that's visually identical to your name. This scanner generates those variants the way an attacker's toolkit would, then checks each one live over DNS to see which are already registered and which publish mail servers. A registered lookalike with MX records is armed: it can send email as a convincing near-copy of you. The tool sorts every variant into a risk map — armed, registered, or available — so the live threats surface first, and shows the punycode behind each Unicode homograph so you can see the deception for what it is.
Registration tells you someone already holds a near-copy of your name; mail servers tell you it's ready to be weaponized. Seeing them mapped turns an abstract worry into a concrete list you can act on — enforce DMARC so nobody sends as your real domain, watch the registered-but-idle ones, and defensively register the obvious gaps. Only the candidate names go out as DNS queries; your brand and the results stay in the browser.
-
Attacker's toolkit
Typos, ASCII homoglyphs, TLD swaps, combosquats, and Unicode homographs — the same families a real permutation engine generates.
-
Armed vs latent
Registration plus MX records means a lookalike can send mail as you — the tool flags those first, above the merely registered and the available.
-
Punycode unmasked
Unicode homographs are shown with the real xn-- name they resolve to, so the visually identical twin is exposed.
-
DNS only
Just candidate domain names go out, as public DNS queries. Your brand and the findings never leave the page.
/ How spoofing works
How does a lookalike domain fool people?
People read shapes, not characters. A recipient skimming an inbox sees the silhouette of your brand and trusts it, which is exactly what a lookalike exploits. The crudest version is a typo the eye autocorrects — a dropped letter, a doubled one, two letters transposed. A step up are the ASCII homoglyphs: rn reads as m, vv as w, the digit one as a lowercase L. At small sizes, on a phone, they're invisible.
The most deceptive class is the Unicode homograph. Many alphabets contain characters drawn identically to Latin letters — the Cyrillic a, e, o, and p are pixel-for-pixel matches. Swap one in and the domain is visually indistinguishable from yours, yet it's a completely different registration that resolves, in DNS, to a punycode name starting with xn--. There's no typo for the eye to catch, which is why browsers and mail clients now try to flag them — and why knowing which twins of your name exist is worth doing before someone else does.
A lookalike only becomes an attack when it's registered and can send mail, and that's the pairing the scanner hunts for. But the defense that neutralizes the whole class isn't registering every variant — it's authentication. A lookalike can never pass DMARC for your real domain, so enforced DMARC stops the most damaging move, sending mail that appears to come from your exact address. The scanner finds the impostors; authentication makes impersonating the genuine article impossible.
/ The defense
You can't register every lookalike, so what actually protects you?
The permutation space is effectively infinite — no one can pre-register every typo, homoglyph, and Unicode twin of their name, and trying is a budget sink. So the strategy is tiered. Defensive registration is worth it for a short list: the handful of obvious typos, the Unicode homograph of your exact name, and the near-miss TLDs your customers might guess. Beyond that, registration stops paying off.
What scales is authentication and monitoring. Enforced DMARC at p=reject means a message forged from your real domain is rejected outright, which removes the highest-impact attack even if a hundred lookalikes exist. Watching the registered lookalikes for a shift to mail-active gives you early warning, and DMARC aggregate reports show you when an unfamiliar source starts sending as you. When a lookalike crosses into active abuse, a takedown request or a UDRP filing removes it. The scan is the reconnaissance; the standing defense is a locked-down authentication posture that makes your genuine domain unforgeable — which is what we operate.
/ Lookalike FAQ
What kinds of lookalikes does it generate?
What makes a lookalike actually dangerous?
How does it check registration and mail?
Why does a Unicode homograph resolve to xn-- something?
What should I do about the ones it finds?
Does anything leave my browser?
The scan finds the impostors. Authentication makes you unforgeable.
You can't register every lookalike, but you can make your real domain impossible to send as. Enforced DMARC, aligned senders, and monitoring for abuse is the standing defense — and it's what we operate. Scan the lookalikes, then let's lock the door.
Book infrastructure reviewRelated capabilities