You
- Tell us your domains, brand names, and what you publish
- Approve or reject each verified match
- Decide when a domain dispute is worth its cost
Roughly a few minutes a week once the queue settles.
How it works
Not a monitoring tool that emails you a list. This is the sequence from the moment a lookalike certificate hits a public log to the moment the URL is verified dead — including the parts that fail.
The first day
Most of this product is a schedule. Here is the whole sequence for a cloned login page, in order, with the one step that is yours marked.
Every publicly-trusted HTTPS certificate is logged, and a credential page needs HTTPS or the browser flags it. That log entry is usually the first trace a clone leaves anywhere — often before the page is even built.
A name that resembles yours proves nothing. We fetch the page and check whether it reproduces your text, loads images straight from your own server, reuses your favicon, and asks for a password. Most candidates fail this and you never see them.
The page body is hashed with SHA-256, the resolving address and response headers are recorded, and the whole thing is timestamped. This has to happen first: the moment an operator suspects they have been reported, the page changes.
Approve, skip, or ask us to hold. Nothing goes out under your name until you have looked. This is the step we will not automate away, because a notice sent to a legitimate business is a liability you would carry.
Registrar, host, CDN, Google Safe Browsing, Microsoft SmartScreen, and the phishing feeds — in parallel, not in sequence. Waiting on a registrar before telling the browser vendors costs a day, and a day is the whole lifetime of these pages.
This is usually the first thing that actually works. Most of the traffic dies here, long before anybody takes the page down — which is why we do not wait for the host to answer.
The case closes when the URL is verified dead, not when an abuse desk says it will look into it. If wave one produces nothing in its window, we escalate to search de-indexing and the payment processor.
Why the results hold up
Review what was copied and where it appeared before approving a notice.
We check registered lookalike domains so you can investigate sites that could impersonate your publication.
We compare the suspect page with your original and preserve evidence for your review.
We look for copied passages from your published work, even when the repost leaves out your brand name.
We filter alternate domains that redirect to your official site, so you spend less time reviewing false alarms.
Evidence
An abuse desk that opens your link and finds a dead page closes the ticket. By the time they read it, the clone has usually moved — so the capture, not the URL, is the case.
Every finding you approve carries this record, and the hash is what lets you assert months later that the page said what you say it said.
Illustrative record. The domain shown is fictional.
Where copies show up
Typosquats, alternate TLDs, and cloned login pages — found through certificate logs and DNS, then opened and checked.
Public channels and “VIP” rooms reselling issues, recordings, indicators, and files.
Public invites to servers that restream courses and drop PDFs to members.
Mega, Drive, Dropbox, MediaFire, and WeTransfer links offering a free copy of paid work.
GitHub, GitLab, npm, and PyPI repositories holding copied source or your sign-in markup.
Gumroad, Whop, Sellix, Patreon, and Ko-fi listings from sellers who are not you.
Scribd, Issuu, and DocDroid uploads of newsletters, research notes, and course material.
Indexed mirrors and reseller pages, plus URLhaus and OpenPhish listings naming your domain.
Private chats are never crawled. We work from public and indexed sources, and route matching invite or landing links to the host instead.
Division of labour
Roughly a few minutes a week once the queue settles.
Nothing to install, and no access to your systems required.
Limits