How it works
We generate the domains an attacker would register against you: a dropped letter, a doubled letter, two letters swapped, a neighbouring key, a hyphen, a look-alike character from another alphabet, a word like secure or invoice bolted on, and the same name on every common ending. Then we ask public DNS which of them exist.
What matters
- Can send mail. The domain has mail servers. Someone can email your staff, customers and suppliers from an address that reads almost like yours.
- Has a website. Often a parked page or a copy of yours, used for phishing logins.
- Registered only. Taken but not in use. Sometimes yours, sometimes an investor, sometimes waiting.
What this cannot tell you
It reads DNS only. A registered look-alike is not proof of anything: some will be yours, some belong to domain investors, some to unrelated businesses. It cannot see a domain that exists but hides from DNS. Treat the list as leads to check, not a verdict.