Free tool
Lookalike domain checker
This free lookalike domain checker generates up to 200 typosquats of your domain (swapped letters, homoglyphs, fat-finger typos, hyphens, other TLDs) and checks each one against public DNS. See which are already registered, and which can receive mail.
This tool runs entirely in your browser: DNS questions go straight to Cloudflare's (or Google's) public DNS-over-HTTPS resolver, and nothing you type here reaches Attack Surface Scan's servers. Only passive, public DNS data is read, and the tool never connects to the domain being checked.
What to do about a registered lookalike domain
A registered lookalike is a lead, not a verdict. Most are parked or held by investors; the ones to act on are recent, mail-capable, or carrying a certificate. Work through it in this order.
- Don't touch it. Don't visit it, email it, or scan it. Visiting tips off whoever runs it and can expose you to whatever it serves. This tool only asks public DNS for the same reason.
- Check certificate transparency. A TLS certificate issued for the lookalike means someone is preparing to serve it over HTTPS. Each registered row links to a crt.sh search for its certificates.
- Treat MX records as the warning sign. A lookalike that can receive mail can carry on a reply-chain conversation with your customers or suppliers, which is how invoice fraud works. Warn finance and anyone who handles payments.
- Report abuse to the registrar. If it is actively phishing, the registrar's and host's abuse desks can suspend it. Send the observed records and dates; trademark disputes (UDRP) are the slower route for names that are merely infringing.
- Consider defensive registration for the handful of variants closest to your brand. You can't register all 200, and you don't need to.
One common misconception: DMARC p=reject protects your own domain from being
spoofed, and it is worth having (check it with the
SPF & DMARC checker). It does nothing for
lookalikes. The attacker owns that domain and can publish perfectly valid email
authentication for it.
How the lookalike domain generator builds candidates
The generator applies seven typosquatting techniques to the name part of your domain, one change at a time, removes duplicates and stops at 200 candidates. It is the same list Attack Surface Scan monitors for verified domains.
| Technique | What changes | Example for example.com |
|---|---|---|
| Swap | Adjacent characters transposed | exmaple.com |
| Omission | One character dropped | exmple.com |
| Repeat | One character doubled | exaample.com |
| Homoglyph | A character replaced by one that looks like it (rn for m, 1 for l, 0 for o) | exarnple.com, examp1e.com |
| Adjacent key | One character replaced by a QWERTY neighbour | exanple.com |
| Hyphenation | A hyphen inserted | exam-ple.com |
| TLD swap | Same name on a popular TLD | example.co, example.net |
Not covered: Unicode (IDN) homographs such as a Cyrillic "a", combosquats like
example-billing.com, and bitsquatting. A long domain name hits the 200
cap before every technique has run, so treat a clean result as "none of these", not
"none at all".
A one-off typosquatting check vs domain impersonation monitoring
A single sweep tells you what exists today. Lookalike campaigns are usually registered days or weeks before the first phishing email, so the useful signal is the change: a name that was not found last week and resolves now, or one that just got a certificate. That needs the same check repeated, with the previous answer remembered, which is what domain impersonation monitoring does.
Questions
What is a lookalike domain?
A domain registered to be mistaken for yours: a swapped or doubled letter
(exmaple.com), a glyph that reads the same in most fonts
(examp1e.com, exarnple.com), a stray hyphen, or your exact name
on a different TLD. Attackers use them for phishing, fake invoices and credential
harvesting pages that pass a quick glance.
Is a registered lookalike always malicious?
No. Many are parked by domain investors, some are defensive registrations your own company made years ago, and some are unrelated businesses with a similar name. Check who holds it before reacting. The ones worth attention are new registrations, ones with an MX record (they can send and receive mail), and ones that get a TLS certificate.
How does this typosquatting checker know a domain is registered?
It asks public DNS-over-HTTPS resolvers for A, NS and MX records. Any answer means the name exists; an NXDOMAIN answer means it does not resolve, which usually means it is unregistered. It is not a WHOIS lookup: a domain that is registered but has no DNS at all shows as not found. The tool never connects to the lookalike itself.
Does DMARC stop lookalike domain phishing?
No. DMARC with p=reject stops people sending mail as your exact domain, and
you should have it. A lookalike is a different domain with its own DNS, so its owner can
publish passing SPF, DKIM and DMARC for it. Protection against lookalikes comes from
spotting them early and from user training, not from your own records.
Can I get alerted when a new lookalike domain is registered?
Yes, that is what domain impersonation monitoring is for. This page is a one-off check. Attack Surface Scan generates the same variants for your verified domains, re-checks them against DNS and certificate transparency on a schedule, and alerts you when one is registered or gets a certificate.
Checked once. Now have it watched.
Lookalikes are registered on the attacker's schedule, not yours. Attack Surface Scan re-checks these variants of your verified domains against DNS and certificate transparency and alerts you when one is registered or gets a certificate, with the evidence a registrar abuse desk needs. How lookalike domain monitoring works.
7-day trial of the full product, no card required. Scanning needs domain ownership verified (DNS record, site file, work email or emailed approval): Attack Surface Scan never scans anything you haven't proved you control.