Skip to main content

Smart Monitoring of Similar Domains

Updated over 2 months ago

Our similar domain monitoring service is always active to protect your brand and your customers. We have an intelligent system that detects domains trying to mimic yours, ensuring that you are one step ahead of potential threats.


How does it work?

Our monitoring focuses on domains that look exactly like your official domain, with some common variations used in phishing and fraud attacks. This includes:

  • Top-Level Domain Variations (TLDs): We detect domains like acme.xyz, which use different extensions but keep the main name the same as yours.

  • Homoglyphs: We identify the use of visually similar characters that can be used to deceive, such as ácme.com.br or acmë.com.

  • Combination of TLDs and Homoglyphs: Our system also detects combinations, like ãcme.info.


What is detected?

To give some clear examples, if your official domain is acme.com.br, we expect to detect variations like:

  • acme.net (TLD Variation)

  • àcme.com.br (Homoglyphs)

  • ácme.info (TLD and Homoglyph Variation)


What is not detected?

It is important to understand that our monitoring does not detect:

  • Domains with more than one token, such as acme-facturas.com.br.

  • Domains that are not exactly the same as the label of your official domain, like acmi.com.br.

  • Domains with other words concatenated, like acmefacturas.com.br.

  • Detections in subdomains, for example, acme.vercel.app.


Dealing with Typosquatting

Typosquatting occurs when someone registers a domain that is a common misspelling of yours, hoping that users will make a mistake when typing and end up on a malicious site. Here's how we handle it:

  • Fraudulent Content: If a typosquatting domain features any fraudulent content, we will immediately open a ticket categorized as Phishing or Fraudulent Use of Brand.

  • Inactive Domain: If the domain has no active content, it will be monitored by our systems for 7 consecutive days. As soon as any content is detected, a ticket for Phishing or Fraudulent Use of Brand will be opened.


How does monitoring help you?

By detecting a similar and malicious domain, a ticket is automatically opened for your team. This speeds up the response process and allows you to act quickly to mitigate risks and prevent crises. There is no need to manually add these domains to quarantine — our system does it for you!


Need to adjust your rules?

If you want to adjust the standard detection rules for your company, you can contact your CSM or our support team at [email protected].


If you have any questions, feel free to reach out at [email protected] 😊

Did this answer your question?