Skip to main content

Hunting Like a Pro: Searches for Similar Domain Names

Updated over 2 months ago

In today's digital threat landscape, protecting your brand and your customers is essential. Axur’s Intelligent Monitoring of Similar Domains enables the detection and takedown of fraudulent domains that attempt to impersonate your company. But how can you perform even more effective and targeted searches to protect your brand?

This article will guide you through four levels of detection, from the most restrictive to the most comprehensive, so you can search like a true professional in Threat Hunting for fraudulent similar domains.


Level 1: Exact Brand Match Domains (Multiple TLDs)

This is the most restrictive level, detecting only domains that exactly match your brand name but use different Top-Level Domains (TLDs). It's ideal for companies looking to catch the most obvious impersonations.

Examples of detection:

  • netflix.cn

  • netflix.co

  • netflix.com.mx

  • netflix.online

Query example:


domainLabel=netflix AND referenceType=DOMAIN


Level 2: Exact Match in Domain Names and Hosts

At this level, the search expands to include exact matches in both domain names and hostnames. This helps identify subdomains or services trying to mimic your brand.

Examples of detection:

  • netflix.com

  • netflix.github.io

  • netflix.co

  • netflix.com.br

Query example:


(domainLabel=netflix OR subdomain=netflix) AND referenceType=DOMAIN


Level 3: Domain and Host Match with Typos and Homoglyphs

Moving up a level, this search includes detection of domains and hosts that use typosquatting (misspellings) and homoglyphs (visually similar characters that deceive users). This is critical for capturing more sophisticated fraud attempts.

Examples of detection:

  • netflíx.com

  • nettflix.github.io

  • netfllx.co

  • online.netflīx.com

Query example:

​(domainLabel=netflix~1 OR sanitizedDomainLabel=netflix~1 OR subdomain=netflix~1 OR sanitizedSubdomain=netflix~1) AND referenceType=DOMAIN

Level 4: Comprehensive Match with Typos and Homoglyphs in Any Position

The most comprehensive level. Here, the search combines typosquatting and homoglyph detection with the ability to find your brand at the beginning, middle, or end of any word used in the domain or host name. Ideal for maximum fraud protection.

Examples of detection:

  • newnetflix.github.io

  • netflis.co

  • ѕuрроrt-netflix.com

  • nētflixlogin.com

Query example:

(domainLabel=*netflix* OR subdomain=*netflix* OR domainLabel=netflix~1 OR subdomain=netflix~1 OR sanitizedDomainLabel=*netflix* OR sanitizedSubdomain=*netflix* OR sanitizedDomainLabel=netflix~1 OR sanitizedSubdomain=netflix~1) AND referenceType=DOMAIN

Need to adjust your rules?

Keep in mind that the ideal detection level depends on your risk profile and available resources. Start with a more conservative level and broaden your scope as needed, monitoring the results and refining your queries to optimize cost-effectiveness and reduce false positives.


If you have any questions, feel free to reach out at [email protected] 😊

Did this answer your question?