This tool helps identify potential domain impersonation threats that could be used to deceive users and damage your brand reputation.
Detection Types 🔤 Homograph Domains Homograph attacks use Unicode characters that look similar to Latin letters but are from different scripts (Cyrillic, Greek, Armenian). Examples:
example.com → еxample.com (Cyrillic 'е' instead of Latin 'e')google.com → gooogle.com (extra 'o')facebook.com → faceboook.com (extra 'o')microsoft.com → microsft.com (missing 'o')amazon.com → amzaon.com (swapped 'a' and 'o')paypal.com → рaypal.com (Cyrillic 'р' instead of Latin 'p')Risk Level: High - These domains can be visually identical to legitimate domains.
🌐 Alternative TLD Domains These variants use the same second-level domain but with different top-level domains:
example.com → example.net, example.org, example.ioIncludes popular gTLDs, country codes, and high-risk TLDs Special attention to suspicious TLDs like .tk, .ml, .ga frequently used in scams Risk Level: Medium to High - Depends on TLD reputation and usage patterns.
⌨️ Typosquatting Domains Domains that exploit common typing mistakes:
Character Omission: example.com → exampe.comCharacter Insertion: example.com → exaample.comCharacter Substitution: example.com → exzmple.com (keyboard proximity)Character Swap: example.com → exmaple.comCharacter Duplication: example.com → exxample.comRisk Level: Medium - Common user errors make these effective for phishing.
Risk Assessment Each detected variant is assigned a risk score (0-100) based on:
Detection Type: Homographs score highest, followed by suspicious TLDsDomain Length: Shorter domains receive higher risk scoresTLD Reputation: Known malicious TLDs increase the scoreScript Mixing: Domains mixing multiple character scripts are flagged as higher riskLow (0-39) Medium (40-69) High (70-89) Critical (90-100)
Best Practices Regular Monitoring: Run detection monthly or when launching new campaignsDomain Registration: Consider registering high-risk variants proactivelyDNS Monitoring: Set up alerts for domain registrations similar to yoursUser Education: Train users to verify URLs carefully, especially for sensitive actionsEmail Security: Implement DMARC, SPF, and DKIM to prevent email impersonationLegal Notice: This tool is for defensive purposes only. Do not register or use detected variants to impersonate legitimate domains. Respect trademark rights and applicable laws.
Export Options Results can be exported in multiple formats for further analysis:
CSV: For spreadsheet analysis and reportingJSON: For programmatic processing and integrationTXT: Simple list format for quick reference