Solution
Domain Impersonation Detection
Find typosquats, homoglyphs, combosquats, and other lookalike domains targeting your brand — before attackers can use them against your customers.
Last reviewed:
What we detect
Typosquats
gogle.com instead of google.com
Domains with common typing errors that users might accidentally visit.
Homoglyphs
gооgle.com (Cyrillic o)
Domains using visually identical characters from different alphabets.
Combosquats
google-login.com
Your brand combined with keywords like login, secure, verify, or support.
TLD variants
google.io, google.co
Your brand registered on different top-level domains.
Bitsquats
googlg.com
Single-bit errors that can occur from hardware faults or cosmic rays.
Hyphenation
goo-gle.com
Your brand split with hyphens to appear legitimate.
Detection sources
Certificate Transparency
Real-time monitoring of CT logs from Google, Cloudflare, and Let's Encrypt. New certificates matching your brand surface within minutes.
Newly Registered Domains
Daily scans of newly registered domain feeds across 18+ TLDs to catch threats before they go live.
Permutation Analysis
Algorithmic generation of lookalike variants using 6+ attack patterns, checked against live DNS.
Evidence Collection
Automated crawling of detected domains to capture screenshots, forms, and brand indicators.
TLD coverage
We scan across 18+ TLDs to catch attackers who register your brand on different extensions:
Frequently asked questions
What is domain impersonation?
Domain impersonation is the registration of domains designed to look like a legitimate brand's domain — typosquats, homoglyphs, combosquats, TLD variants, bitsquats, and hyphenated names — so users mistake them for the real site. Attackers use them for credential harvesting, fake stores, and phishing before the brand notices.
What is a typosquat?
A typosquat is a domain that is a common misspelling or typing error of a legitimate brand name — for example gogle.com instead of google.com — registered in the hope that users will accidentally visit it. Variants include missing characters, adjacent-key errors, transposed characters, and added characters.
What is a homoglyph domain?
A homoglyph domain uses characters that look visually identical to a brand name but are actually different Unicode characters — for example Cyrillic "о" in gооgle.com instead of Latin "o" — making it nearly impossible to spot by eye. Detecting homoglyphs requires analyzing domain names at the Unicode level, not visual inspection.
How does lookalike domain detection work?
impersona.io combines four sources: real-time monitoring of Certificate Transparency logs from Google, Cloudflare, and Let's Encrypt; daily scans of newly registered domain feeds across 18+ TLDs; algorithmic permutation analysis that generates lookalike variants using 6+ attack patterns and checks them against live DNS; and automated crawling of detected domains to capture screenshots, forms, and brand indicators.
Which TLDs does impersona.io scan?
18+ top-level domains, including .com, .net, .org, .io, .co, .xyz, .info, .us, .biz, .dev, .app, .de, .uk, .eu, .ai, .tech, .online, and .site. Scanning multiple TLDs catches attackers who register a brand name on a different extension, such as google.io or google.co, instead of the original domain.
Find domains impersonating your brand
Run a free brand check to see what lookalike domains exist right now. No signup required.