Skip to main content

Smart Monitoring of Similar Domains

Our similar domain monitoring service is always active to protect your brand and your customers. It automatically detects domains trying to mimic yours, so you stay one step ahead of potential threats; no manual setup is required.


How does it work?

Our system monitors domains that look like your official domain using four types of detection:

  • TLD-squat: Detects domains that use your exact brand name but with a different extension, like netflix.cn or netflix.shop.

  • Homoglyphs: Identifies domains that replace letters with visually similar characters to deceive users, such as using a Cyrillic "п" instead of a Latin "n", resulting in a domain that looks identical to yours at a glance.

  • Typosquats: Catches domains built on common typing mistakes, such as swapping, removing, or transposing a letter, like netflx.com or netlfix.com.

  • Combosquats: Finds domains that pair your brand name with other words to appear legitimate, such as netflixlogin.com or mynetflix.shop.


What is detected?

For example, if your official domain is netflix.com, our monitoring can detect variations like the following:

  • netflix.cn — TLD-squat

  • пetflix.com — Homoglyph (Cyrillic character)

  • netflx.com — Typosquat

  • netflixlogin.com — Combosquat

  • netflx.cn — TLD-squat + Typosquat

  • netflxlogin.top — Combosquat + Typosquat

Which combinations are active depends on your rule configuration. See Refining your rules below.


What is not detected?

Detections in subdomains, for example, netflix.vercel.app, are outside the scope of this monitoring.


Your default rule

Every monitoring rule comes pre-configured with a default query that combines TLD-squat and homoglyph detection:

(domain=netflix.* OR sanitizedDomain=netflix.*)

This covers the most common impersonation patterns with a low false positive rate, and no configuration is needed on your end.

To expand or adjust the detection scope, go to Settings and use the Refine rule section for that monitoring rule.


Refining your rules

You can adjust what your monitoring detects directly from Settings, without contacting support. Each monitoring rule has a "Refine rule" section where you can configure the domain similarity checks.

Detection type checkboxes

  • Include homoglyphs

    • Adds matching against the normalized version of the domain, catching look-alike character substitutions

  • Include typosquats

    • Catches domains that are one character edit away from your brand name (e.g. a swap, deletion, or insertion)

  • Include combosquats

    • Finds domains that contain your brand name anywhere,  before or after other words

  • Only email-enabled domains

    • Limits results to domains that have an active MX record, a strong indicator of phishing infrastructure.

Each combination updates the Monitored query field in real time, showing the exact query that will be applied to your rule.


Monitored query

The Monitored query field shows the Lucene query generated by your checkbox selections. You do not need to edit it manually — the checkboxes handle this for you. Use it to verify what is being monitored and to understand the query before simulating.


Average results

Below the query, you will see how many results per day your current configuration has been averaging over the last 15 days. This helps you gauge whether your rule is too broad (too many results, higher false positive risk) or too narrow (few results, potentially missing threats).


Simulate in Threat Hunting

The Simulate in Threat Hunting link opens your current query directly in the Threat Hunting interface, letting you preview the results before saving. This is the recommended step before applying any change to your rule.


Advanced mode

The Advanced mode toggle unlocks the query field for manual editing. Use this when you need a detection configuration that goes beyond the standard checkboxes, for example, adding extra DNS conditions or combining fields in a custom way.


Dealing with Typosquatting

Typosquatting occurs when someone registers a domain that is a common misspelling of yours, hoping users will make a mistake when typing and end up on a malicious site. Here's how we handle it:

  • Fraudulent content: If a typosquatting domain features any fraudulent content, we will immediately open a ticket categorized as Phishing or Fraudulent Brand Use

  • Inactive domain: If the domain has no active content, it will be monitored by our systems for 7 consecutive days. As soon as any content is detected, a ticket for Phishing or Fraudulent Brand Use will be opened.


How does monitoring help you?

By detecting a similar and malicious domain, a ticket is automatically opened for your team. This speeds up the response process and allows you to act quickly to mitigate risks and prevent crises. There is no need to manually add these domains to quarantine; our system does it for you.


If you have any questions, feel free to reach out at [email protected] 😊

Did this answer your question?