Find lookalikes
Up to 150 candidates are checked over DNS-over-HTTPS. A domain that returns nameservers is registered; one with MX can send mail.
How it works
Generate
Omissions, transpositions, repeated and adjacent-key characters, homoglyphs like rn for m and 0 for o, hyphenations, common affixes and TLD swaps — capped at 150.
Resolve
Each candidate is queried for NS, A and MX over DNS-over-HTTPS. Nameservers or an SOA in the authority section mean it is registered.
Rank
Registered domains with MX come first: they can receive and usually send mail. Then registered without mail, then the free ones worth taking.
Act
Defensive registrations get a redirect plus spf -all and p=reject, so they exist but cannot be used.
What DMARC cannot stop
A p=reject policy on your domain means nobody can send mail that claims to be from acme.co. It says nothing about acrne.co, acme-secure.co or acme.com, which are different domains that anyone can register for nine dollars and authenticate perfectly. Those are what phishing kits actually use, and what a prospect sees in a From line when they are reading on a phone. This tool generates the ones that matter and tells you which already exist.
Reading the results
Registration alone is not a threat; half the internet's short names are squatted. The signal is MX. A lookalike with a mail server can receive replies to spoofed messages and, unless its owner published SPF and DMARC, can send them too. Check the nameservers: MarkMonitor, CSC and the other brand-protection registrars mean the real company registered it defensively, and that is a good sign rather than a bad one. A lookalike on cheap nameservers with a fresh MX at a bulk email provider is the one to escalate.
Defensive registration, done properly
For a sending fleet I register the exact-TLD swaps and the two or three homoglyphs that read identically in a sans-serif font, then treat them as mail-disabled domains: a web redirect to the real site, v=spf1 -all, a DMARC record with p=reject, and a null MX. That costs under fifty dollars a year and removes the cheapest attacks. Registering every candidate on the list is not worth it; watching it once a quarter is.
The cold email angle
Outbound teams get this from the other side. A secondary sending domain that is too close to another company's name is a lookalike of theirs, and if that company runs brand monitoring you will receive a takedown letter rather than a reply. Run the secondary domain finder candidates through this check before buying — a name that has homoglyph neighbours with MX records at a bank is a name to skip.
Frequently asked questions
What is a homoglyph domain?
One that swaps characters for lookalikes: rn for m, 0 for o, 1 for l, vv for w. acrne.co and acme.co are indistinguishable in many fonts.
How does the tool know a domain is registered?
It queries NS, A and MX over DNS. Any answer, or an SOA for the domain in the authority section, means a zone exists. Domains that return NXDOMAIN with the parent's SOA are unregistered.
Should I register every lookalike?
No. Register the exact TLD swaps and the homoglyphs that read identically, disable mail on them, and watch the rest. Squatters hold thousands of the others and most never become a problem.
Can DMARC protect against lookalike domains?
No. DMARC protects the exact domain in the From header. A lookalike is a different domain with its own DMARC, which the attacker controls.
Why does it check MX rather than WHOIS?
WHOIS is rate-limited and cannot be queried from a browser. MX is the record that matters: it tells you whether the lookalike can receive mail, which is what a phishing operation needs.
Last reviewed
What to run next
The checks that most often follow this one.
More in this category
Guides that go deeper
When the tools tell you something is wrong
The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.
Deliverability rescue
Mail landing in spam, replies gone quiet, or a domain suddenly blocked. I find the actual cause rather than guessing, and fix it.
- Authentication and alignment failures
- Blocklist delistings and reputation repair
- Gateway and filter-level blocks
- A written report on what broke and why
Email & sending infrastructure
Sending domains, inboxes, authentication and warmup, built to survive volume instead of burning down in a month.
- Domain and inbox fleets at any scale
- SPF, DKIM, DMARC and tracking domains
- Google Workspace — Silver Partner
- Handover documentation you actually own
Domain, DNS & migration
Changing registrar, mail provider or host without a day of downtime or a week of mail silently failing.
- Registrar and nameserver moves
- Workspace and Microsoft 365 migrations
- MX, SSL and subdomain cutover
- Staged rollout with rollback at every step
Monitoring & retainer
Infrastructure drifts. Records get edited, certificates expire, domains get listed. Ongoing eyes on the fleet.
- Scheduled checks across every domain
- Alerts before your clients notice
- Monthly reporting
- Priority response when something breaks
Start with a call
Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.
Thirty minutes, no pitch
We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.