Typosquatting Detection
Every D3 scan generates all plausible lookalike domain variants using 12 mutation techniques, DNS-verifies each one, and cross-references registered variants against WHOIS data to distinguish defensive registrations (same owner) from external threats.
The 12 mutation techniques
droping.comOne character removed from the SLD.
dmoain.comTwo adjacent characters swapped.
d0main.comASCII homoglyphs: o→0, i→1, s→5.
domaain.comExtra character inserted at any position.
doomaan.comAny character repeated consecutively.
xomain.comQWERTY keyboard neighbour substituted.
do-main.comHyphen inserted at any position.
domain.netSame SLD, different TLD.
domain-login.comBrand name combined with common keywords.
dοmain.comCyrillic or Greek lookalike characters (xn-- Punycode). Visually identical — highest phishing risk.
rnodern.comThe character pair 'rn' is visually identical to 'm' in many fonts.
damain.comEach vowel replaced with every other vowel.
Risk scoring per variant
IDN/Unicode homoglyph — visually indistinguishable from the original. Active website or MX records present.
Homoglyph or substitution variant. Domain actively resolves — likely in use for phishing or BEC.
Registered variant with DNS activity. Adjacent key, transposition or omission technique.
Registered but no active DNS. Likely defensively registered or parked.
Brand Monitoring
Typosquatting detection runs when you trigger a scan. Brand Monitoring runs continuously — processing ICANN zone files overnight so you are alerted the moment a new lookalike domain is registered, before the attacker can activate it.
Coverage note: Brand Monitoring via CZDS covers gTLDs that participate in ICANN's zone file access programme (.com, .net, .org and hundreds of others). ccTLDs (.nl, .de, .be etc.) are not covered by CZDS. Real-time domain scan detection covers all 1081 TLDs.
Reputation & Blocklist Checks
Every D3 scan checks the domain and its resolved IP addresses against four authoritative threat intelligence feeds. A listed domain or IP is a strong indicator of phishing, spam infrastructure or malware distribution — relevant both for evaluating a target domain and for verifying the reputation of your own.
Spamhaus Block List — IP addresses that have sent spam or are under the control of spam operators.
Exploits Block List — IP addresses of hijacked PCs, proxy servers and third-party exploits.
Domain Block List — domains found in spam messages, operated by spammers or listed for other policy reasons.
Google's threat intelligence feed for phishing pages, malware distribution sites and unwanted software.
Run a scan on your brand now
Free account. 3 trial credits. No credit card required.