Catch the fake domains before they phish you.
Attackers register a lookalike of your brand right before a phishing or invoice-fraud run. We watch new domain registrations and certificate transparency, score how weaponized each one is, and page you only when one turns dangerous.
No agentNo DNS changesTwo-minute setup
- acmee[.]comtypo · registeredclear
- acme[.]cotld swap · parkedclear
- acmе[.]comhomoglyph · cert 2hwatching
- acme-login[.]comlive · mx · cert 2hthreat
This is what lands when a lookalike turns dangerous.
No fear, no noise. Every alert carries the defanged domain, the signals that make it weaponized, and the timeline that got it there — so you can act in seconds, not open an investigation.
shown defanged — never a live link
Why this is dangerous
A live sign-in page is up and the domain can send mail. It is staged for credential phishing or invoice fraud aimed at your staff and customers.
Recommended actions
- Warn staff and customers to expect it
- File abuse with the registrar and host
- Watch for escalation as signals change
Weaponization signals
- ResolvesA record → live host
- Can send mailMX records present
- Live siteHTTP 200 · sign-in form detected
- Fresh certificateTLS issued 2h ago · seen in CT
Timeline
- 6h agoDomain registered
- 2h agoTLS certificate issued (seen in CT log)
- 1h agoSign-in page went live
- just nowYou were paged
From brand name to a single, earned alert.
Three steps, no deployment. You never install an agent, change DNS, or grant access to anything.
- 01
Add your brand
Type the name you protect — like "acme". We derive its typos, homoglyphs, TLD swaps, and combosquats for you. Your own domains fold in free as verified aliases.
- 02
We watch the feeds
We match new domain registrations and certificate transparency against your brand, continuously. A baseline scan surfaces lookalikes that already exist within minutes.
- 03
You get paged only when it matters
Quiet registrations rest in a digest. The loud channel — Slack, Teams, webhook, or email — fires only when a lookalike shows signs of being weaponized.
Every way a name gets faked — from one brand.
Add the name you protect and we generate and match all of it, continuously, against live registration and certificate streams.
Typos
A slipped, doubled, or swapped key — the miss a hurried person never notices.
Homoglyphs & IDN
Unicode look-alikes that render as your name but register as another. We surface the true punycode.
TLD swaps
Your exact name under a different ending — the one you did not think to register.
Combosquats
Your brand plus a word that borrows trust — login, support, secure, pay, hr.
Bitsquats
A single flipped bit in memory or a cache lands a real user on a neighbor of your name.
One brand covers all of it
You add acme once. We watch every class here — and bill you per brand, never per lookalike or per domain you already own.
Built to stay quiet until it shouldn't.
The whole product is tuned against alert fatigue. Loud only when earned, calm by default, and honest about what it shows you.
Severity-routed alerts
New registrations rest in a quiet digest. The loud channel fires only on weaponization, and you choose which channel hears which tier.
Baseline scan on day one
Adding a brand immediately scans for lookalikes that already exist — it usually surfaces the first findings within minutes, not after the next feed cycle.
Evidence and a timeline
Every finding carries the defanged domain, its punycode twin, the weaponization signals, and a plain-English reason it is dangerous.
Allowlist and calm defaults
Know a domain is fine? Allowlist it and it stays quiet. Sensible defaults mean you are not tuning knobs to get signal instead of noise.
MSP multi-brand workspaces
Watch many client brands from one workspace, each with its own routing. Built for managed providers who defend more than their own name.
Free verified aliases
Your own same-name domains — acme.io, acme.co.uk — fold in as verified aliases at no charge. You pay per brand, not per domain you already own.
Pay per brand you protect.
One price that scales with you — graduated so each extra brand costs less. Billed per distinct name you defend, not per lookalike we find, and never for the domains you already own. Watching one brand covers every way that name gets faked.
or $190/yr · 2 months free
Graduated pricing — your first brand is $19/mo, brands 2–10 are $9/mo each, and 11+ brands are $7/mo each. You only pay for the brands you protect.
- All lookalike classes: typos, homoglyphs, TLD swaps, combosquats
- Baseline scan on day one, then continuous monitoring
- Severity-routed alerts to email, Slack, Teams, or webhook
- Evidence, punycode twins, and finding timelines
- Free verified aliases for the domains you already own
No free plan and no metered surprises. Change your brand count anytime — billing runs through Polar, our merchant of record.
What to know before you start.
The unglamorous truths, up front. If it matters to your decision, it belongs here.
Do you take the fake sites down?
Not in v1. You get the alert, the evidence, and recommended actions — warn your people, file abuse with the registrar and host, and watch for escalation. Automated takedown is on the roadmap; we would rather ship the honest version than promise enforcement we do not yet run.
What don't you catch?
We match on name-likeness, so content-only impersonation with no similarity to your name is out of scope. A phishing page at secure-payments-portal[.]com that never uses “acme” is invisible to us. We would rather be precise about names than drown you in guesses about page content.
Do I need to install anything?
No. No agent, no browser extension, no DNS changes, and no access to your accounts. You add a brand name; we watch public domain-registration and certificate-transparency streams on your behalf.
Then why does verification mention a DNS record?
Monitoring never touches your DNS — a brand starts watching the moment you add it, and folding a same-name domain in as a free alias (or ignoring any finding) takes effect immediately, with no proof required. Verification is entirely optional: it just marks a domain as confirmed yours and shows a Verified badge — nothing else depends on it. If you want that badge, you choose the proof: a one-line DNS TXT record or a signed link sent to the domain's standard admin addresses. Either way there are no ongoing DNS changes.
What's the difference between a brand and a domain?
A brand is a name you protect, like acme. Watching it covers that name's typos, homoglyphs, TLD swaps, and combosquats. Your own same-name domains — acme.io, acme.co.uk — fold in free as owned aliases. You are billed per brand, not per domain you own.
How fast will I see results?
The baseline scan runs the moment you add a brand and usually surfaces existing lookalikes within minutes. After that, new registrations and certificates are matched continuously as the feeds update.
Where does the data come from?
Certificate Transparency logs and newly-registered-domain feeds — public streams that need no cooperation from an attacker and no access to you. Nothing is read from your systems.
Start watching your brand in two minutes.
Add a name, choose where alerts land, and let the baseline scan go to work. No agent, no DNS changes, no sales call.
Start monitoringSelf-serve · cancel anytime · from $19/mo per brand