Skip to content

Feature

Visual Clone Detection

Detect credential-harvesting pages that visually clone your login pages. Screenshot comparison, DOM analysis, and brand asset matching identify fake sites before customers get hurt.

Last reviewed:

Screenshot capture

Full-page screenshots of suspected domains, timestamped and stored as evidence.

DOM analysis

Structural analysis of page HTML to detect login forms, brand keywords, and suspicious elements.

Brand asset matching

Detection of brand logos, color schemes, and visual patterns that indicate impersonation.

Form analysis

Identification of credential input fields and analysis of form submission destinations.

Risk indicators

Flagging of high-risk patterns: recent registration, privacy proxy, suspicious hosting.

How visual clone detection works

1. Domain discovery

impersona.io continuously monitors for lookalike domains via Certificate Transparency logs, newly registered domain feeds, and permutation analysis. Every suspected domain is queued for crawling.

2. Safe crawling

Suspected domains are crawled in isolated containers. We capture screenshots, extract DOM content, record HTTP headers, and analyze page structure without exposing your infrastructure.

3. Content analysis

The captured content is analyzed for credential-harvesting indicators: login forms, brand keywords, visual similarity to known brand assets, and suspicious form destinations.

4. Risk scoring

Each finding receives a risk score based on multiple signals. The AI explains which indicators triggered the alert — no black-box scoring.

What we detect

Cloned login pages

Fake sign-in forms mimicking your authentication flow

Brand impersonation sites

Sites using your logos, colors, and brand language

Credential input forms

Password fields with suspicious submission targets

Redirect chains

Multi-step redirects designed to evade detection

Frequently asked questions

What is visual clone detection?

Visual clone detection identifies credential-harvesting pages that visually mimic a brand — fake login pages built to look like yours. It works by capturing full-page screenshots of suspected domains, analyzing the DOM for login forms and brand keywords, and matching brand assets such as logos and color schemes against the captured page.

How is visual clone detection different from domain monitoring?

Domain monitoring surfaces suspicious names — lookalike domains found via Certificate Transparency logs, newly registered domain feeds, and permutation analysis. Visual clone detection goes a step further: it crawls those domains and analyzes what each page actually renders — screenshots, DOM structure, forms, and brand assets — to determine whether the site is impersonating yours rather than just resembling its name.

Is crawling suspected domains safe for my infrastructure?

Yes — suspected domains are crawled in isolated containers, never from your network. impersona.io captures screenshots, extracts DOM content, records HTTP headers, and analyzes page structure without exposing your infrastructure to the potentially malicious site. The captured material then feeds content analysis and risk scoring.

What kinds of cloned pages does it detect?

Four main categories: cloned login pages that mimic your authentication flow, brand impersonation sites using your logos, colors, and brand language, credential input forms whose password fields submit to suspicious destinations, and multi-step redirect chains designed to evade detection.

How are findings scored?

Each finding receives a risk score based on multiple signals — login forms, brand keyword matches, visual similarity to known brand assets, recent registration, privacy-proxy registration, and suspicious hosting. The AI explains which indicators triggered the alert, so there is no black-box scoring to interpret.

Find cloned pages targeting your brand

Run a free brand check to surface lookalike domains. Verify your domain to access visual comparison and detailed evidence.