# Domain Typosquat Audit (`conserving_mastodon/domain-typosquat-audit`) Actor

Brand protection in one call: generate lookalike domains for a brand (typos, transpositions, homoglyphs, hyphenation, TLD swaps) and check via DNS which are actually registered. The registered lookalikes are your threat list for phishing and brand abuse. Charged only on completed audits.

- **URL**: https://apify.com/conserving\_mastodon/domain-typosquat-audit.md
- **Developed by:** [Chris Arsenault](https://apify.com/conserving_mastodon) (community)
- **Categories:** Business, Developer tools, Automation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$250.00 / 1,000 completed audits

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## Domain Typosquat Audit

**Which lookalikes of your domain are already registered?** One call generates the domains a phisher or brand-abuser would register — single-character typos, transpositions, homoglyphs (o→0, l→1, rn→m), hyphenations, and TLD swaps (.com → .net, .co, .io, .app and more) — then checks each one against live DNS and hands you the list that actually exists.

### What you get

Summary plus one row per generated lookalike:

```json
{
  "domain": "example.com",
  "candidates_checked": 40,
  "registered_lookalikes": 7,
  "threats": ["example.net", "example.co", "examp1e.com", "exmaple.com"],
  "note": "Registered lookalikes are not necessarily malicious, but each is a domain someone else controls that resembles yours."
}
```

```json
{ "domain": "examp1e.com", "kind": "homoglyph", "state": "REGISTERED" }
```

### Use cases

- **Brand protection**: the registered-lookalike list is the starting point for takedowns, monitoring, and defensive registrations.
- **Phishing readiness**: know which convincing lookalikes already exist before one is used against your customers.
- **Agents doing security due diligence**: a brand-exposure snapshot as one tool call, re-runnable on a schedule to catch new registrations.

### How registration is checked

A domain with a live DNS zone (an NS/SOA/A answer, or NOERROR) is treated as registered even if it is parked; a domain that returns NXDOMAIN is available. Checks run over public DNS-over-HTTPS, concurrently, so a full sweep takes seconds.

### Honesty notes

- Registration state is DNS-derived (fast and reliable for the "does it exist" question); it does not include WHOIS ownership details.
- Candidate generation covers the highest-risk variation patterns, capped at 40 for a fast, focused sweep; it is not an exhaustive permutation of every possible string.
- A malformed input domain is rejected free; billing is per completed audit.

Built by 1450 Enterprises, alongside Domain Intel and the DNS Records Audit.

# Actor input Schema

## `domain` (type: `string`):

The brand domain to protect (e.g. example.com). Lookalikes are generated from its label.

## Actor input object example

```json
{
  "domain": "example.com"
}
```

# Actor output Schema

## `results` (type: `string`):

Summary: candidates checked, registered lookalike count, and the threat list. Then one row per generated lookalike with its variation kind and registration state.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domain": "example.com"
};

// Run the Actor and wait for it to finish
const run = await client.actor("conserving_mastodon/domain-typosquat-audit").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domain": "example.com" }

# Run the Actor and wait for it to finish
run = client.actor("conserving_mastodon/domain-typosquat-audit").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domain": "example.com"
}' |
apify call conserving_mastodon/domain-typosquat-audit --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,conserving_mastodon/domain-typosquat-audit"
        }
    }
}

```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/lWLjQVLJOKSabCTzR/builds/ZHL8TjAltnC4uHGa8/openapi.json
