Watch

The attack
enforcement cannot stop.

At p=reject nobody can forge your domain, so attackers register one that looks like it. That domain passes every authentication check, because it is authenticating as itself. So we watch for them.

Lookalikes · acme.comExample

1,842 candidates checked Mon · 4 registered · certificate transparency checked today

  • acme-billing.comReported 14 msgs · MX · SPF · cert Aug 21Keyword
  • acrne.comMX · SPF · registered 12 days agoHomoglyph
  • acme.coNS · registered 2016Ending
  • acme-hr.comNS · MX · registered 2019Keyword

What the scan finds, and how it grades it

Evidence, not guesses. Every row says what was checked, when, and why it is the color it is.

Up to 2,000 imitations

Typos, swapped and doubled letters, look-alike characters including Cyrillic ones, added words like billing or hr, other endings like .co and .cm, and your name folded into a subdomain. Ordered by how attackers actually pick them.

Graded by what it can do

Name servers, a mailbox, a sending policy, a certificate, and the registration date, read from public DNS, certificate transparency, and the registry. A row is critical when receivers saw it send as you, or when it can send mail and is under 90 days old.

What it will not do

It never calls a registered domain an attack: an old neighbor that happens to take mail is a warning, not a crisis. It never fetches the lookalike's website, and it is not a takedown service.

Receiver evidence

Your own DMARC reports are read the same way. A lookalike that already sent as you shows up the moment a receiver reports it, with the message count, and that row is critical whatever DNS says. Receiver-confirmed rows accrue on every plan, because they cost nothing to read.

A critical row raises an action and an alert on every channel you have on. Mark the rows that are yours or a partner's and they go quiet, still visible. Claim one you want and it becomes a protected domain. For the rest, copy the evidence pack, open it in your own mail client, and it is already addressed to the registrar's abuse contact.

Nothing to set up

1

Every protected domain, weekly

Each verified domain is scanned once a week, and a domain with an active lookalike gets a daily certificate re-check. Up to three manual scans a day on top.

2

Read the Lookalikes tab

Registered imitations, the rule that generated each, its evidence, and the registrar and abuse contact from the registry. The tab always states what was checked and when.

3

Ignore, claim, or report

Three actions per row. Ignored rows stay stored and stop alerting until you restore them. The report is a mailto: draft, so nothing leaves our systems in your name.

Parked names and null-MX domains are never critical: a domain that says it takes no mail is not a mailbox. Certificate transparency being unreachable is shown, not hidden.

See who is
pretending to be you.

Add a domain and the receiver-confirmed rows are live on every plan. Lite adds the weekly scan of up to 2,000 imitations.