How it works

A clone lives for hours. So the schedule is the product.

Not a monitoring tool that emails you a list. This is the sequence from the moment a lookalike certificate hits a public log to the moment the URL is verified dead — including the parts that fail.

The first day

What actually happens, and when.

Most of this product is a schedule. Here is the whole sequence for a cloned login page, in order, with the one step that is yours marked.

  1. T+0

    A certificate is issued for a name that resembles yours

    Every publicly-trusted HTTPS certificate is logged, and a credential page needs HTTPS or the browser flags it. That log entry is usually the first trace a clone leaves anywhere — often before the page is even built.

  2. Within minutes

    We open it and decide whether it is a copy

    A name that resembles yours proves nothing. We fetch the page and check whether it reproduces your text, loads images straight from your own server, reuses your favicon, and asks for a password. Most candidates fail this and you never see them.

  3. Immediately after

    Evidence is sealed before anyone is told

    The page body is hashed with SHA-256, the resolving address and response headers are recorded, and the whole thing is timestamped. This has to happen first: the moment an operator suspects they have been reported, the page changes.

  4. You decide

    You see the match and the evidenceYour call

    Approve, skip, or ask us to hold. Nothing goes out under your name until you have looked. This is the step we will not automate away, because a notice sent to a legitimate business is a liability you would carry.

  5. Within the hour

    Every authority is notified at once

    Registrar, host, CDN, Google Safe Browsing, Microsoft SmartScreen, and the phishing feeds — in parallel, not in sequence. Waiting on a registrar before telling the browser vendors costs a day, and a day is the whole lifetime of these pages.

  6. Often under an hour

    Chrome starts showing a red interstitial

    This is usually the first thing that actually works. Most of the traffic dies here, long before anybody takes the page down — which is why we do not wait for the host to answer.

  7. Until it is gone

    We re-check rather than assume

    The case closes when the URL is verified dead, not when an abuse desk says it will look into it. If wave one produces nothing in its window, we escalate to search de-indexing and the payment processor.

Why the results hold up

A lookalike name is a lead. Evidence is what gets it taken down.

Review what was copied and where it appeared before approving a notice.

Find lookalike sites

We check registered lookalike domains so you can investigate sites that could impersonate your publication.

Check the page

We compare the suspect page with your original and preserve evidence for your review.

Match your writing

We look for copied passages from your published work, even when the repost leaves out your brand name.

Reduce false alarms

We filter alternate domains that redirect to your official site, so you spend less time reviewing false alarms.

Evidence

This is what a registrar will act on.

An abuse desk that opens your link and finds a dead page closes the ticket. By the time they read it, the clone has usually moved — so the capture, not the URL, is the case.

Every finding you approve carries this record, and the hash is what lets you assert months later that the page said what you say it said.

evidence recordconfirmed clone
url
https://acme-pay-signin.top/login
captured_at
2026-09-01T14:22:07ZBefore any notice was sent
resolved_ip
198.51.100.44
http_status
200
body_sha256
9f2c…a41eWhat makes the capture hold up after the page is gone
text_containment
0.87Share of your copy reproduced verbatim
hotlinked_assets
acmepay.com/logo.svgLoading images from your own server
favicon_match
true
credential_form
truePassword field posting off-site
classification
confirmed_clone

Illustrative record. The domain shown is fictional.

Where copies show up

The places your customers were never meant to land.

Lookalike domains

Typosquats, alternate TLDs, and cloned login pages — found through certificate logs and DNS, then opened and checked.

Telegram

Public channels and “VIP” rooms reselling issues, recordings, indicators, and files.

Discord

Public invites to servers that restream courses and drop PDFs to members.

File and cloud hosts

Mega, Drive, Dropbox, MediaFire, and WeTransfer links offering a free copy of paid work.

Code and package registries

GitHub, GitLab, npm, and PyPI repositories holding copied source or your sign-in markup.

Creator marketplaces

Gumroad, Whop, Sellix, Patreon, and Ko-fi listings from sellers who are not you.

Document hosts

Scribd, Issuu, and DocDroid uploads of newsletters, research notes, and course material.

Search and phishing feeds

Indexed mirrors and reseller pages, plus URLhaus and OpenPhish listings naming your domain.

Private chats are never crawled. We work from public and indexed sources, and route matching invite or landing links to the host instead.

Division of labour

Three decisions are yours. The rest is ours.

You

  • Tell us your domains, brand names, and what you publish
  • Approve or reject each verified match
  • Decide when a domain dispute is worth its cost

Roughly a few minutes a week once the queue settles.

Us

  • Watch certificate logs, DNS, chat platforms, file hosts, and search continuously
  • Open every candidate and prove it is a copy before showing it to you
  • Preserve hashed, timestamped evidence that survives the page being deleted
  • Send and track every notice, and escalate when one is ignored
  • Verify removal, reopen if it returns, and report the timings

Nothing to install, and no access to your systems required.

Limits

What this does not do

  • It does not guarantee removal. Registrars in some jurisdictions ignore notices and bulletproof hosts exist. We commit to speed, escalation depth, and telling you which cases are stuck — not to an outcome we do not control.
  • It does not reach private groups. We find what is publicly reachable. Any vendor claiming to see inside closed channels is describing something you should not want attached to your name.
  • It is not legal advice. We prepare evidence and notices. A lawyer files a lawsuit, and we will refer you to one when that is the honest next step.
  • It will tell you when it found nothing. A clean week is reported as a clean week. If a data source is down, the scan says it could not look rather than reporting an all-clear it did not earn.