Domain Typosquat Audit avatar

Domain Typosquat Audit

Pricing

$250.00 / 1,000 completed audits

Go to Apify Store
Domain Typosquat Audit

Domain Typosquat Audit

Brand protection in one call: generate lookalike domains for a brand (typos, transpositions, homoglyphs, hyphenation, TLD swaps) and check via DNS which are actually registered. The registered lookalikes are your threat list for phishing and brand abuse. Charged only on completed audits.

Pricing

$250.00 / 1,000 completed audits

Rating

0.0

(0)

Developer

Chris Arsenault

Chris Arsenault

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

Which lookalikes of your domain are already registered? One call generates the domains a phisher or brand-abuser would register — single-character typos, transpositions, homoglyphs (o→0, l→1, rn→m), hyphenations, and TLD swaps (.com → .net, .co, .io, .app and more) — then checks each one against live DNS and hands you the list that actually exists.

What you get

Summary plus one row per generated lookalike:

{
"domain": "example.com",
"candidates_checked": 40,
"registered_lookalikes": 7,
"threats": ["example.net", "example.co", "examp1e.com", "exmaple.com"],
"note": "Registered lookalikes are not necessarily malicious, but each is a domain someone else controls that resembles yours."
}
{ "domain": "examp1e.com", "kind": "homoglyph", "state": "REGISTERED" }

Use cases

  • Brand protection: the registered-lookalike list is the starting point for takedowns, monitoring, and defensive registrations.
  • Phishing readiness: know which convincing lookalikes already exist before one is used against your customers.
  • Agents doing security due diligence: a brand-exposure snapshot as one tool call, re-runnable on a schedule to catch new registrations.

How registration is checked

A domain with a live DNS zone (an NS/SOA/A answer, or NOERROR) is treated as registered even if it is parked; a domain that returns NXDOMAIN is available. Checks run over public DNS-over-HTTPS, concurrently, so a full sweep takes seconds.

Honesty notes

  • Registration state is DNS-derived (fast and reliable for the "does it exist" question); it does not include WHOIS ownership details.
  • Candidate generation covers the highest-risk variation patterns, capped at 40 for a fast, focused sweep; it is not an exhaustive permutation of every possible string.
  • A malformed input domain is rejected free; billing is per completed audit.

Built by 1450 Enterprises, alongside Domain Intel and the DNS Records Audit.