Free check, no sign-up

Who is pretending to be you?

Attackers register a domain that looks like yours, then email your customers from it. This finds the look-alikes that already exist. Nothing is logged.

Runs in your browser against public DNS. We do not see the domain you check.

How it works

We generate the domains an attacker would register against you: a dropped letter, a doubled letter, two letters swapped, a neighbouring key, a hyphen, a look-alike character from another alphabet, a word like secure or invoice bolted on, and the same name on every common ending. Then we ask public DNS which of them exist.

What matters

  • Can send mail. The domain has mail servers. Someone can email your staff, customers and suppliers from an address that reads almost like yours.
  • Has a website. Often a parked page or a copy of yours, used for phishing logins.
  • Registered only. Taken but not in use. Sometimes yours, sometimes an investor, sometimes waiting.

What this cannot tell you

It reads DNS only. A registered look-alike is not proof of anything: some will be yours, some belong to domain investors, some to unrelated businesses. It cannot see a domain that exists but hides from DNS. Treat the list as leads to check, not a verdict.