Skip to content
24/7 Emergency Response Line
en
Services
Solutions
Research
Company
ToolsTrust Center

Phishing Risk Checker

Attackers register addresses that look almost exactly like your domain to fool your customers and staff: one letter missing, two letters swapped, or “-support” added at the end. This tool generates those variants and checks which ones are actually registered.

Queries are not stored. The tools use public information only; client-side tools never send your data anywhere.

What this tool checks

  • Other TLDs (.com, .net, .io, .com.tr …)
  • Missing, doubled or swapped letters
  • Adjacent-key typos
  • Look-alike characters (o→0, l→1, m→rn)
  • Added words such as “-login” or “secure-”
  • Web (A) and mail (MX) records on registered variants

How to use it

  1. 01

    Enter your own domain.

  2. 02

    Press Check; hundreds of variants are tested over DNS.

  3. 03

    Review look-alikes with mail servers first and request takedowns where needed.

Technical details

Detecting registration

A variant counts as registered if DNS returns authoritative name servers (NS) for it. A and MX records then show whether it hosts a website or mail infrastructure.

Risk level

Look-alikes with MX records are the highest risk: they can send convincing email in your name. Ones with only a website can host fake login pages.

Limits

The tool covers the most common techniques and checks a limited number of variants. Internationalized (IDN) homograph domains and continuous monitoring are part of our brand protection service.

Frequently asked questions

I found a look-alike domain — what now?

First review its owner and content (the WHOIS Lookup tool helps). If it's being abused, send abuse reports to the registrar and hosting provider; with trademark rights you can start a UDRP procedure.

Should I buy every look-alike?

Not all of them. Registering the riskiest ones defensively (main TLDs, single-letter typos) is sensible; monitoring is more efficient for the rest.

Does DMARC protect me from this?

No. DMARC only stops spoofing of your own domain. Mail from a look-alike domain can have perfectly valid SPF/DMARC of its own, so look-alike monitoring is needed separately.

How fresh are the results?

Checks use live DNS queries; results are cached for a few hours.