Find lookalikes

Up to 150 candidates are checked over DNS-over-HTTPS. A domain that returns nameservers is registered; one with MX can send mail.

How it works

acme.co · 118 candidates
acrne.cohomoglyph · MX presentCAN SEND
acme.comTLD swap · registeredPARKED
acme-secure.coaffix · unregisteredFREE
acmee.corepetition · unregisteredFREE
The one with MX is the one a phishing kit would use. Everything else is a watch list.
01

Generate

Omissions, transpositions, repeated and adjacent-key characters, homoglyphs like rn for m and 0 for o, hyphenations, common affixes and TLD swaps — capped at 150.

02

Resolve

Each candidate is queried for NS, A and MX over DNS-over-HTTPS. Nameservers or an SOA in the authority section mean it is registered.

03

Rank

Registered domains with MX come first: they can receive and usually send mail. Then registered without mail, then the free ones worth taking.

04

Act

Defensive registrations get a redirect plus spf -all and p=reject, so they exist but cannot be used.

What DMARC cannot stop

A p=reject policy on your domain means nobody can send mail that claims to be from acme.co. It says nothing about acrne.co, acme-secure.co or acme.com, which are different domains that anyone can register for nine dollars and authenticate perfectly. Those are what phishing kits actually use, and what a prospect sees in a From line when they are reading on a phone. This tool generates the ones that matter and tells you which already exist.

Reading the results

Registration alone is not a threat; half the internet's short names are squatted. The signal is MX. A lookalike with a mail server can receive replies to spoofed messages and, unless its owner published SPF and DMARC, can send them too. Check the nameservers: MarkMonitor, CSC and the other brand-protection registrars mean the real company registered it defensively, and that is a good sign rather than a bad one. A lookalike on cheap nameservers with a fresh MX at a bulk email provider is the one to escalate.

Defensive registration, done properly

For a sending fleet I register the exact-TLD swaps and the two or three homoglyphs that read identically in a sans-serif font, then treat them as mail-disabled domains: a web redirect to the real site, v=spf1 -all, a DMARC record with p=reject, and a null MX. That costs under fifty dollars a year and removes the cheapest attacks. Registering every candidate on the list is not worth it; watching it once a quarter is.

The cold email angle

Outbound teams get this from the other side. A secondary sending domain that is too close to another company's name is a lookalike of theirs, and if that company runs brand monitoring you will receive a takedown letter rather than a reply. Run the secondary domain finder candidates through this check before buying — a name that has homoglyph neighbours with MX records at a bank is a name to skip.

Frequently asked questions

What is a homoglyph domain?

One that swaps characters for lookalikes: rn for m, 0 for o, 1 for l, vv for w. acrne.co and acme.co are indistinguishable in many fonts.

How does the tool know a domain is registered?

It queries NS, A and MX over DNS. Any answer, or an SOA for the domain in the authority section, means a zone exists. Domains that return NXDOMAIN with the parent's SOA are unregistered.

Should I register every lookalike?

No. Register the exact TLD swaps and the homoglyphs that read identically, disable mail on them, and watch the rest. Squatters hold thousands of the others and most never become a problem.

Can DMARC protect against lookalike domains?

No. DMARC protects the exact domain in the From header. A lookalike is a different domain with its own DMARC, which the attacker controls.

Why does it check MX rather than WHOIS?

WHOIS is rate-limited and cannot be queried from a browser. MX is the record that matters: it tells you whether the lookalike can receive mail, which is what a phishing operation needs.

Last reviewed

Related tools

What to run next

The checks that most often follow this one.

Domains & web

More in this category

Read more

Guides that go deeper

Services

When the tools tell you something is wrong

The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.

Get in touch

Start with a call

Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.

Thirty minutes, no pitch

We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.

Based inRangpur, Bangladesh — all time zones
RepliesWithin one business day
PartnerGoogle Workspace Silver
Back to top