Feature
Visual Clone Detection
Detect credential-harvesting pages that visually clone your login pages. Screenshot comparison, DOM analysis, and brand asset matching identify fake sites before customers get hurt.
Last reviewed:
Screenshot capture
Full-page screenshots of suspected domains, timestamped and stored as evidence.
DOM analysis
Structural analysis of page HTML to detect login forms, brand keywords, and suspicious elements.
Brand asset matching
Detection of brand logos, color schemes, and visual patterns that indicate impersonation.
Form analysis
Identification of credential input fields and analysis of form submission destinations.
Risk indicators
Flagging of high-risk patterns: recent registration, privacy proxy, suspicious hosting.
How visual clone detection works
1. Domain discovery
impersona.io continuously monitors for lookalike domains via Certificate Transparency logs, newly registered domain feeds, and permutation analysis. Every suspected domain is queued for crawling.
2. Safe crawling
Suspected domains are crawled in isolated containers. We capture screenshots, extract DOM content, record HTTP headers, and analyze page structure without exposing your infrastructure.
3. Content analysis
The captured content is analyzed for credential-harvesting indicators: login forms, brand keywords, visual similarity to known brand assets, and suspicious form destinations.
4. Risk scoring
Each finding receives a risk score based on multiple signals. The AI explains which indicators triggered the alert — no black-box scoring.
What we detect
Cloned login pages
Fake sign-in forms mimicking your authentication flow
Brand impersonation sites
Sites using your logos, colors, and brand language
Credential input forms
Password fields with suspicious submission targets
Redirect chains
Multi-step redirects designed to evade detection
Frequently asked questions
What is visual clone detection?
Visual clone detection identifies credential-harvesting pages that visually mimic a brand — fake login pages built to look like yours. It works by capturing full-page screenshots of suspected domains, analyzing the DOM for login forms and brand keywords, and matching brand assets such as logos and color schemes against the captured page.
How is visual clone detection different from domain monitoring?
Domain monitoring surfaces suspicious names — lookalike domains found via Certificate Transparency logs, newly registered domain feeds, and permutation analysis. Visual clone detection goes a step further: it crawls those domains and analyzes what each page actually renders — screenshots, DOM structure, forms, and brand assets — to determine whether the site is impersonating yours rather than just resembling its name.
Is crawling suspected domains safe for my infrastructure?
Yes — suspected domains are crawled in isolated containers, never from your network. impersona.io captures screenshots, extracts DOM content, records HTTP headers, and analyzes page structure without exposing your infrastructure to the potentially malicious site. The captured material then feeds content analysis and risk scoring.
What kinds of cloned pages does it detect?
Four main categories: cloned login pages that mimic your authentication flow, brand impersonation sites using your logos, colors, and brand language, credential input forms whose password fields submit to suspicious destinations, and multi-step redirect chains designed to evade detection.
How are findings scored?
Each finding receives a risk score based on multiple signals — login forms, brand keyword matches, visual similarity to known brand assets, recent registration, privacy-proxy registration, and suspicious hosting. The AI explains which indicators triggered the alert, so there is no black-box scoring to interpret.
Find cloned pages targeting your brand
Run a free brand check to surface lookalike domains. Verify your domain to access visual comparison and detailed evidence.