free tool

typosquatting checker.

Generate the typos, homoglyphs, and TLD swaps that could impersonate a client domain. See which are registered and which are configured for email before the client sees the phish.

what it checks

The domains attackers register to be mistaken for you.

Typosquatting is registering a domain that looks almost like yours to catch mistyped URLs and impersonate you in email. We enumerate the common variations, then resolve each one against DNS.

keyboard typos

Missing, repeated, and swapped characters, plus fat-finger substitutions and insertions based on which keys sit next to each other on a QWERTY keyboard.

look-alike characters

Homoglyphs that read as one another in common fonts: rn for m, vv for w, cl for d, and digit-for-letter swaps like 0 for o and 1 for l.

vowel and hyphen tricks

Swapped vowels (paypel for paypal) and added or removed hyphens, both cheap ways to land a domain that still reads correctly at a glance.

TLD swaps

Your exact name on a different extension — .net, .co, .io, .org and more — which is one of the most common and convincing impersonation tricks.

added words

Names padded with words like login, secure, account, and support, the phrasing phishing pages use to look official.

live registration & mail

Every candidate is resolved against DNS. Registered domains are flagged, and MX records surface the ones configured to receive email — a strong abuse signal.

why it matters

A registered look-alike is a loaded weapon.

email impersonation

A look-alike configured for mail can support convincing impersonation. To a hurried employee or customer, invoice@paypel.com looks close enough to trust.

phishing & credential theft

Attackers clone your login page on a near-identical domain. Victims who mistype your URL, or click a lookalike link, hand over passwords without noticing the swap.

traffic and brand theft

Even parked, a typo domain siphons visitors to ads or competitors and erodes trust in your brand every time someone lands somewhere they didn't expect.

it happens quietly

Registrations are cheap and silent. The first time most teams learn a look-alike exists is when a customer forwards a phishing email that used it.

faq

Typosquatting questions, answered.

beyond look-alikes

Look-alikes are one part of the client domain.

The free scan checks look-alikes, email auth & DMARC, SSL & domain expiry, and blacklists together from public records. One result, no signup.

related checks

Keep checking the same failure point.

Use the related tools one at a time, or run all four posture checks together.