Domain Impersonation Monitor — Live Look-alike Domains avatar

Domain Impersonation Monitor — Live Look-alike Domains

Pricing

from $20.00 / 1,000 live look-alike domain founds

Go to Apify Store
Domain Impersonation Monitor — Live Look-alike Domains

Domain Impersonation Monitor — Live Look-alike Domains

Find typosquatting and look-alike domains impersonating your brand that are actually live — confirmed by DNS resolution, MX records and the TLS certificate each one serves, not merely registered. Covers homoglyph, bitsquat, combosquat and TLD-swap variants. No WHOIS, so no personal data.

Pricing

from $20.00 / 1,000 live look-alike domain founds

Rating

0.0

(0)

Developer

SStudio

SStudio

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

4 days ago

Last modified

Categories

Share

Domain Impersonation Monitor

Most look-alike domain tools tell you what is registered. Registered means almost nothing — squatters register thousands and park them. This one tells you which look-alikes are live: resolving in DNS, able to receive mail, and serving a TLS certificate right now.

Give it your domain. It builds every plausible impersonation of it, checks each one, and returns only the ones that are actually standing up — ranked by how dangerous they look.

What it checks

For every candidate domain:

SignalWhat it means
DNS A / AAAA recordsSomeone is pointing this name at a server
NS recordsThe domain is registered even if it has no host yet
MX recordsIt can receive e-mail — it is set up for phishing
TLS certificate on port 443Someone stood up a real HTTPS site, not a parked page
Certificate trustedThe certificate chains to a public root
Certificate covers the domainThe CN or a SAN entry actually matches

Techniques

omission · repetition · transposition · replacement (QWERTY neighbours) · insertion · homoglyph (rn→m, l→1, o→0 …) · hyphenation · bitsquatting (single-bit memory flips) · combosquatting (brand-login, secure-brand …) · tld-swap

Risk score — the exact formula, no black box

+1 resolves in DNS
+2 has MX records (can receive mail)
+1 serves a TLS certificate
+1 that certificate is trusted
+1 that certificate covers this domain

5-6 = high · 3-4 = medium · 1-2 = low

Nothing is inferred beyond those five facts. There is no model, no guess, no scraped reputation feed.

Output

One row per live look-alike: brandDomain, lookalikeDomain, technique, riskLevel, riskScore, resolved, ipAddresses, mxRecords, nameServers, tlsCertificate, tlsSubject, tlsIssuer, tlsTrusted, certCoversDomain, tlsValidFrom, tlsValidTo, sanCount, checkedAt.

Billing

You are charged per live look-alike domain found — not per candidate generated, and not per run. A brand whose look-alikes are all dead costs you almost nothing.

Where the data comes from

  • DNS — standard port-53 resolution. No third-party DNS-over-HTTPS API is used.
  • TLS certificates — read directly from the candidate host during an ordinary HTTPS handshake. No certificate aggregator or search service is used.
  • Public suffix handling — a subset of the Public Suffix List (Mozilla Public License 2.0).

No WHOIS or RDAP lookups are performed, so no domain registrant personal data is collected, stored, or returned.

Limits

  • Public suffix coverage is a common subset, not the full list. Exotic multi-part suffixes may split imprecisely.
  • IDN / punycode homograph variants are not generated in this version.
  • A domain behind a CDN or a wildcard-parking provider can serve a valid certificate without hosting a real impersonation site — the certificate fields are returned so you can judge.
  • checkedAt is a point-in-time observation. Re-run on a schedule to catch new ones.