Lookalike domain alerts: how we rank them

Lookalike monitoring looks for domains someone could register to impersonate yours, checks which of them exist, and warns you about the ones that look dangerous. It is included on the Professional and MSP plans and during your free trial, but not on the free Starter plan. Anyone can still run a one-off lookalike check with our free tools.

Setting it up

Open the domain from Domains, go to its Checks section, choose + Add a check, then Lookalike Monitoring and Set up. On Starter, the check offers an upgrade instead. The first scan starts within about half an hour and can take up to a day to fill in. After that it runs once a day. The region is set from your domain's ending: .co.uk gives UK, .de gives EU, .com.au gives APAC and .com gives Global.

Which lookalikes we check

We take your brand name, the part of your domain before the ending, and build the variations an attacker is most likely to use:

  • Your exact name on other endings chosen for your region. A UK monitor checks .com, .net, .org, .co.uk, .uk, .org.uk, .me.uk and .io. A Global monitor, such as one for a .com domain, checks .com, .net, .org, .co, .io and .co.uk.
  • Typing mistakes on your own ending: a missing, doubled or swapped letter, a changed vowel, an added or removed hyphen, a plural, or a dot inserted into the name.
  • Look-alike characters such as 0 for o, 1 for l, rn for m and vv for w.
  • Phishing words joined to your name with a hyphen: login, secure, account, verify, mail, portal, pay and support, as in yourbrand-login or secure-yourbrand.

Domains that are already in your ShieldMarc account are never reported as lookalikes. For each variation we check whether it is registered. Registered ones are listed with their age, DMARC policy, whether they have mail (MX) records, and their registrar.

How each lookalike is ranked

  • Critical: registered in the last 30 days. We email you the first time we see it.
  • Warning: registered 31 to 90 days ago. We email you the first time we see it.
  • Watch: older than 90 days, or a domain whose registration date we cannot find. Listed on the dashboard, never emailed.
  • Established: over a year old and unlikely to be a threat, or one you have acknowledged or claimed. Collapsed on the dashboard, never emailed.

A lookalike that publishes its own DMARC reject policy, or whose name is shorter than five characters, is treated as unlikely to be a threat. It is shown as Watch, or Established once it is over a year old, and it never triggers an email.

Registration age matters most because a domain registered years ago with a name like yours is usually a real business, while fraud campaigns tend to start within weeks of registration. We email only for endings that matter in your region, and always for your own ending. Others are listed without an email.

When a lookalike starts accepting mail

If a Critical or Warning lookalike we have already emailed you about adds mail (MX) records, we send one extra alert: it can now receive replies to mail sent in your name. Mail records are rechecked every couple of days, so this alert can arrive a day or two after the change.

Working the list

  • Acknowledge moves a lookalike to Established and stops all emails about it, including the mail-record alert. It sticks across future scans.
  • I own this is for domains that are yours. It adds the domain to your account, where it is listed under Claimed Domains.

Finding your results

Alert emails link to your domain's lookalike list. A new Critical lookalike also appears on your Home to-do list and under the domain's status. To open the full list, go to the domain's Checks section, choose Lookalike Monitoring, then your domain.