Our similar domain monitoring service is always active to protect your brand and your customers. It automatically detects domains trying to mimic yours, so you stay one step ahead of potential threats; no manual setup is required.
How does it work?
Our system monitors domains that look like your official domain using four types of detection:
TLD-squat: Detects domains that use your exact brand name but with a different extension, like netflix.cn or netflix.shop.
Homoglyphs: Identifies domains that replace letters with visually similar characters to deceive users, such as using a Cyrillic "п" instead of a Latin "n", resulting in a domain that looks identical to yours at a glance.
Typosquats: Catches domains built on common typing mistakes, such as swapping, removing, or transposing a letter, like netflx.com or netlfix.com.
Combosquats: Finds domains that pair your brand name with other words to appear legitimate, such as netflixlogin.com or mynetflix.shop.
What is detected?
For example, if your official domain is netflix.com, our monitoring can detect variations like the following:
netflix.cn — TLD-squat
пetflix.com — Homoglyph (Cyrillic character)
netflx.com — Typosquat
netflixlogin.com — Combosquat
netflx.cn — TLD-squat + Typosquat
netflxlogin.top — Combosquat + Typosquat
Which combinations are active depends on your rule configuration. See Refining your rules below.
What is not detected?
Detections in subdomains, for example, netflix.vercel.app, are outside the scope of this monitoring.
Your default rule
Every monitoring rule comes pre-configured with a default query that combines TLD-squat and homoglyph detection:
(domain=netflix.* OR sanitizedDomain=netflix.*)
This covers the most common impersonation patterns with a low false positive rate, and no configuration is needed on your end.
To expand or adjust the detection scope, go to Settings and use the Refine rule section for that monitoring rule.
Refining your rules
You can adjust what your monitoring detects directly from Settings, without contacting support. Each monitoring rule has a "Refine rule" section where you can configure the domain similarity checks.
Detection type checkboxes
Include homoglyphs
Adds matching against the normalized version of the domain, catching look-alike character substitutions
Include typosquats
Catches domains that are one character edit away from your brand name (e.g. a swap, deletion, or insertion)
Include combosquats
Finds domains that contain your brand name anywhere, before or after other words
Only email-enabled domains
Limits results to domains that have an active MX record, a strong indicator of phishing infrastructure.
Each combination updates the Monitored query field in real time, showing the exact query that will be applied to your rule.
Monitored query
The Monitored query field shows the Lucene query generated by your checkbox selections. You do not need to edit it manually — the checkboxes handle this for you. Use it to verify what is being monitored and to understand the query before simulating.
Average results
Below the query, you will see how many results per day your current configuration has been averaging over the last 15 days. This helps you gauge whether your rule is too broad (too many results, higher false positive risk) or too narrow (few results, potentially missing threats).
Simulate in Threat Hunting
The Simulate in Threat Hunting link opens your current query directly in the Threat Hunting interface, letting you preview the results before saving. This is the recommended step before applying any change to your rule.
Advanced mode
The Advanced mode toggle unlocks the query field for manual editing. Use this when you need a detection configuration that goes beyond the standard checkboxes, for example, adding extra DNS conditions or combining fields in a custom way.
Dealing with Typosquatting
Typosquatting occurs when someone registers a domain that is a common misspelling of yours, hoping users will make a mistake when typing and end up on a malicious site. Here's how we handle it:
Fraudulent content: If a typosquatting domain features any fraudulent content, we will immediately open a ticket categorized as Phishing or Fraudulent Brand Use
Inactive domain: If the domain has no active content, it will be monitored by our systems for 7 consecutive days. As soon as any content is detected, a ticket for Phishing or Fraudulent Brand Use will be opened.
How does monitoring help you?
By detecting a similar and malicious domain, a ticket is automatically opened for your team. This speeds up the response process and allows you to act quickly to mitigate risks and prevent crises. There is no need to manually add these domains to quarantine; our system does it for you.
If you have any questions, feel free to reach out at [email protected] 😊
