Skip to content

Solution

Domain Impersonation Detection

Find typosquats, homoglyphs, combosquats, and other lookalike domains targeting your brand — before attackers can use them against your customers.

Last reviewed:

What we detect

Typosquats

gogle.com instead of google.com

Domains with common typing errors that users might accidentally visit.

Homoglyphs

gооgle.com (Cyrillic o)

Domains using visually identical characters from different alphabets.

Combosquats

google-login.com

Your brand combined with keywords like login, secure, verify, or support.

TLD variants

google.io, google.co

Your brand registered on different top-level domains.

Bitsquats

googlg.com

Single-bit errors that can occur from hardware faults or cosmic rays.

Hyphenation

goo-gle.com

Your brand split with hyphens to appear legitimate.

Detection sources

Certificate Transparency

Real-time monitoring of CT logs from Google, Cloudflare, and Let's Encrypt. New certificates matching your brand surface within minutes.

Newly Registered Domains

Daily scans of newly registered domain feeds across 18+ TLDs to catch threats before they go live.

Permutation Analysis

Algorithmic generation of lookalike variants using 6+ attack patterns, checked against live DNS.

Evidence Collection

Automated crawling of detected domains to capture screenshots, forms, and brand indicators.

TLD coverage

We scan across 18+ TLDs to catch attackers who register your brand on different extensions:

.com.net.org.io.co.xyz.info.us.biz.dev.app.de.uk.eu.ai.tech.online.site

Frequently asked questions

What is domain impersonation?

Domain impersonation is the registration of domains designed to look like a legitimate brand's domain — typosquats, homoglyphs, combosquats, TLD variants, bitsquats, and hyphenated names — so users mistake them for the real site. Attackers use them for credential harvesting, fake stores, and phishing before the brand notices.

What is a typosquat?

A typosquat is a domain that is a common misspelling or typing error of a legitimate brand name — for example gogle.com instead of google.com — registered in the hope that users will accidentally visit it. Variants include missing characters, adjacent-key errors, transposed characters, and added characters.

What is a homoglyph domain?

A homoglyph domain uses characters that look visually identical to a brand name but are actually different Unicode characters — for example Cyrillic "о" in gооgle.com instead of Latin "o" — making it nearly impossible to spot by eye. Detecting homoglyphs requires analyzing domain names at the Unicode level, not visual inspection.

How does lookalike domain detection work?

impersona.io combines four sources: real-time monitoring of Certificate Transparency logs from Google, Cloudflare, and Let's Encrypt; daily scans of newly registered domain feeds across 18+ TLDs; algorithmic permutation analysis that generates lookalike variants using 6+ attack patterns and checks them against live DNS; and automated crawling of detected domains to capture screenshots, forms, and brand indicators.

Which TLDs does impersona.io scan?

18+ top-level domains, including .com, .net, .org, .io, .co, .xyz, .info, .us, .biz, .dev, .app, .de, .uk, .eu, .ai, .tech, .online, and .site. Scanning multiple TLDs catches attackers who register a brand name on a different extension, such as google.io or google.co, instead of the original domain.

Find domains impersonating your brand

Run a free brand check to see what lookalike domains exist right now. No signup required.