Domain Impersonation Monitor — Live Look-alike Domains
Pricing
from $20.00 / 1,000 live look-alike domain founds
Domain Impersonation Monitor — Live Look-alike Domains
Find typosquatting and look-alike domains impersonating your brand that are actually live — confirmed by DNS resolution, MX records and the TLS certificate each one serves, not merely registered. Covers homoglyph, bitsquat, combosquat and TLD-swap variants. No WHOIS, so no personal data.
Pricing
from $20.00 / 1,000 live look-alike domain founds
Rating
0.0
(0)
Developer
SStudio
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
4 days ago
Last modified
Categories
Share
Domain Impersonation Monitor
Most look-alike domain tools tell you what is registered. Registered means almost nothing — squatters register thousands and park them. This one tells you which look-alikes are live: resolving in DNS, able to receive mail, and serving a TLS certificate right now.
Give it your domain. It builds every plausible impersonation of it, checks each one, and returns only the ones that are actually standing up — ranked by how dangerous they look.
What it checks
For every candidate domain:
| Signal | What it means |
|---|---|
| DNS A / AAAA records | Someone is pointing this name at a server |
| NS records | The domain is registered even if it has no host yet |
| MX records | It can receive e-mail — it is set up for phishing |
| TLS certificate on port 443 | Someone stood up a real HTTPS site, not a parked page |
| Certificate trusted | The certificate chains to a public root |
| Certificate covers the domain | The CN or a SAN entry actually matches |
Techniques
omission · repetition · transposition · replacement (QWERTY neighbours) · insertion · homoglyph (rn→m, l→1, o→0 …) · hyphenation · bitsquatting (single-bit memory flips) · combosquatting (brand-login, secure-brand …) · tld-swap
Risk score — the exact formula, no black box
+1 resolves in DNS+2 has MX records (can receive mail)+1 serves a TLS certificate+1 that certificate is trusted+1 that certificate covers this domain
5-6 = high · 3-4 = medium · 1-2 = low
Nothing is inferred beyond those five facts. There is no model, no guess, no scraped reputation feed.
Output
One row per live look-alike: brandDomain, lookalikeDomain, technique, riskLevel, riskScore, resolved, ipAddresses, mxRecords, nameServers, tlsCertificate, tlsSubject, tlsIssuer, tlsTrusted, certCoversDomain, tlsValidFrom, tlsValidTo, sanCount, checkedAt.
Billing
You are charged per live look-alike domain found — not per candidate generated, and not per run. A brand whose look-alikes are all dead costs you almost nothing.
Where the data comes from
- DNS — standard port-53 resolution. No third-party DNS-over-HTTPS API is used.
- TLS certificates — read directly from the candidate host during an ordinary HTTPS handshake. No certificate aggregator or search service is used.
- Public suffix handling — a subset of the Public Suffix List (Mozilla Public License 2.0).
No WHOIS or RDAP lookups are performed, so no domain registrant personal data is collected, stored, or returned.
Limits
- Public suffix coverage is a common subset, not the full list. Exotic multi-part suffixes may split imprecisely.
- IDN / punycode homograph variants are not generated in this version.
- A domain behind a CDN or a wildcard-parking provider can serve a valid certificate without hosting a real impersonation site — the certificate fields are returned so you can judge.
checkedAtis a point-in-time observation. Re-run on a schedule to catch new ones.