What Brand Protection Means for Domains
Brand protection is the practice of finding and shutting down domains that impersonate your company — typosquats, lookalikes, and cloned sites used to phish customers, intercept email, or sell counterfeit goods. In domain terms, it comes down to three moves: register the variations that matter, monitor for the ones attackers register, and act fast when a malicious lookalike goes live.
The threat is simple to grasp. Your customers trust your name. An attacker who controls `examp1e.com` or `example-support.net` borrows that trust to steal credentials, payments, or data — and your brand takes the blame. Below is how the abuse works, how to spot it, and what to do.
How Domain Abuse Actually Works
Attackers register domains that a human eye or a distracted click will confuse with yours. The tactics fall into a handful of recognizable patterns.
- Character substitution and omission: swapping or dropping letters — `exmaple.com`, `exampple.com`, `exampl.com`. These catch typos and glancing readers.
- Homoglyphs and IDN spoofing: replacing a Latin letter with a near-identical character from another script (a Cyrillic "а" for a Latin "a"). Rendered in a browser, `exаmple.com` looks identical to the real thing but resolves somewhere else entirely.
- TLD swaps: taking your exact name on a different extension — `example.co`, `example.io`, `example.app` — when you only own `.com`.
- Combosquatting: appending words that feel official — `example-login.com`, `secure-example.net`, `example-billing.com`. No typo required; the brand name is spelled correctly, which makes it especially convincing.
- Subdomain tricks: burying your brand in a subdomain of a domain they control — `example.com.verify-account.net`. The real domain is `verify-account.net`, but the leftmost text reads like yours.
- Hyphenation and pluralization: `ex-ample.com`, `examples.com`, `theexample.com`.
Once a lookalike is registered, the attacker weaponizes it in one of a few ways. They point MX records at a mail server so the domain can send email that appears to come from your organization — the backbone of business email compromise and phishing. They provision a TLS certificate (free and automatic today) so the fake site loads with a padlock and no browser warning, which most users read as "safe." And they clone your login page, harvest whatever visitors enter, and either sell it or use it directly.
Why These Attacks Succeed
They work because they exploit trust and inattention, not technical flaws. A padlock icon convinces people a site is legitimate even though TLS only proves the connection is encrypted, not that the operator is honest. Homoglyph domains defeat visual inspection entirely. And email spoofing succeeds anywhere SPF, DKIM, and DMARC aren't strictly enforced — many domains publish these records in a permissive "monitor only" mode that never actually blocks forged mail.
The window matters too. A typosquat can be registered, given a certificate, and loaded with a phishing kit within hours. By the time a customer complains, the damage is done. That's why passive defense — hoping no one notices your brand — fails, and why monitoring is the core of real brand protection.
How to Spot a Typosquat or Impersonation Domain
You can catch many lookalikes by knowing the signals. Use this as a detection checklist:
- Recent registration date paired with your brand name. A domain containing your name that was registered days ago and has no history is a red flag.
- A live TLS certificate on a domain you don't own. Certificate issuance is logged publicly in certificate transparency logs the moment a cert is created — a lookalike getting a certificate often signals it's about to go live.
- MX records configured on a lookalike. A domain that can receive and send email is being set up to impersonate your staff, not to host a harmless parked page.
- Privacy-shielded or mismatched WHOIS data. Attackers hide behind privacy services or register under details that don't match any real business.
- A page that mirrors your branding — your logo, color scheme, or copied login form on a domain that isn't yours.
- Nameservers or hosting in regions inconsistent with your real infrastructure, or bulk registration where one owner holds dozens of variants of your name.
Checking these signals by hand across every possible permutation of your brand is impractical — there are thousands of plausible variants once you combine substitutions, TLDs, and combosquat words. This is exactly the work Dokyma automates: it generates the full permutation space for your name, then checks each candidate's DNS records, WHOIS details, MX configuration, and certificate transparency history to surface the ones that are actually registered and active. You review a ranked list instead of guessing.
How to Protect Your Brand From Domain Abuse
A durable defense combines a few things you do yourself with continuous monitoring you don't.
Register the variations that matter
You can't buy every permutation, and you shouldn't try. Focus on high-risk registrations:
- The common TLDs for your market — at minimum `.com`, plus `.net`, `.org`, and the country codes where you operate.
- The obvious typos a real customer would make — a dropped letter, a doubled letter, a transposed pair.
- Your exact name on any new TLD that fits your industry.
Point every defensive registration at your real site or a holding page, and enable registrar lock so no one can transfer them away without verification.
Lock down your email
Publish SPF, DKIM, and DMARC records, and set your DMARC policy to `reject` — not just `none` — once you've confirmed your legitimate mail passes. This tells receiving servers to discard forged mail claiming to be from your domain, which shuts down a huge category of impersonation.
Monitor continuously
Registration is a one-time act; abuse is ongoing. Attackers register new variants constantly, soa defense that isn't watched decays the moment you close the spreadsheet. Continuous monitoring means someone — or something — watches for new registrations, fresh certificates, and MX changes on lookalike domains around the clock, and flags them while there's still time to act.
Dokyma runs this monitoring for you: it tracks the permutation space of your brand, watches certificate transparency logs for new lookalike certificates, and alerts you when a matching domain gets DNS, mail, or hosting that signals it's about to be used against your customers.
Act fast when you find one
When you confirm a malicious lookalike:
- Document it — capture the page, the WHOIS record, the certificate, and any phishing content as evidence.
- Report abuse to the domain's registrar and hosting provider; both have policies against phishing and impersonation and can suspend the domain.
- Warn your customers if the site is actively phishing, so no one enters credentials while takedown is in progress.
- File a UDRP or URS complaint for domains that clearly infringe your trademark and can't be resolved through abuse reports.
Speed is the whole game. A lookalike taken down within hours does little damage; one that lives for weeks can burn your reputation and your customers' accounts.
Your Next Step
Start by seeing what already exists. Run a free brand scan at dokyma.com — it generates the typosquats and lookalikes of your name, checks which ones are registered, and shows you their DNS, WHOIS, MX, and certificate activity so you know exactly which domains are impersonating you today. From there, you can register the gaps that matter and set up monitoring to catch the next one before your customers do.