Lookalike Domains Browser
5 min
the lookalike domains browser lists all lookalike domains detected for your organization in one place each domain is shown as a single record that brings together all its events, so instead of tracking individual events in your feed, you can view every detected domain and its relevant events in a single view you can browse, sort, filter, and search every detected domain, open a consolidated profile for any one of them, and act by viewing a site in the sandbox or submitting a takedown request key features broad detection coverage lookalike domains are discovered from a broad set of sources, including open source tooling and specialized external providers detected domains are enriched with additional attributes such as whois records, mx records, and dns records, giving you more context on each domain for more information on how domains are detected, see how detection works docid\ acmt78djtn8vkuzelrmfw domain intelligence profile each lookalike domain has a domain intelligence profile that gathers everything known about it in one place the screenshot, favicon, and metadata, the enrichment collected from parent and update events, the full event history, and a severity timeline from the profile you can see a timeline of how a domain's severity has changed over time and which events drove the change visual similarity detection lookalike domains are also detected by visual similarity, which finds sites that resemble your brand even when the domain name is not similar this catches impersonation that text based domain matching alone would miss managed takedowns when you confirm that a lookalike domain is malicious, you can submit a takedown request and track it through to resolution for more information on takedowns, see takedown services docid\ s0i javxqnhtxdhxrdsr using the lookalike domains browser click through the following product tour to learn how to use the lookalike domains browser view lookalike domains navigate to the lookalike domains browser from the left navigation each row in the browser represents one lookalike domain, not a single event, and shows the following information severity the severity assigned to the domain, from \<font color="#2166ae">`info`\</font> to \<font color="#b91c1c">`critical`\</font> , reflecting how closely it resembles your domain and how likely it is to be a threat domain the url of the detected lookalike domain registered at the date the domain was registered, where known registrar the registrar the domain was registered through, where known related domain the domain identifier that the lookalike domain resembles sources the detection source or sources that surfaced the domain, such as certstream, dnstwist, or datapulse a domain can be found by more than one mx records the mail exchange records configured for the domain, where present mx records indicate the domain is set up to send or receive mail discovered at the date the domain was first detected for you updated at the date of the most recent event on the domain sort, filter, and search use filters to focus on the domains that matter to you, for example the most recently discovered domains, the domains updated most recently, or the domains registered within a recent time period you can also search to find a specific lookalike domain view the domain intelligence profile select a lookalike domain to open its domain intelligence profile the profile brings together the parent event and all related update events, along with any screenshots, its metadata, and its severity history take action and view severity timeline in the domain actions section, select submit a takedown request to open a takedown request for the domain select view in sandbox to investigate the domain because a lookalike domain may host malicious content, this opens the site in an isolated environment so you can see how it looks and behaves without visiting it directly takedown services and sandbox require an add on please contact your csm for more information view event history in event history , you can see all the events detected for this domain click view event to see the details in the events feed best practices start from the browser to investigate lookalike domains when you are reviewing lookalike domains, start from the lookalike domains browser rather than the events feed the browser lets you work from the domain level down to individual changes identify the domains relevant to you, open the domain intelligence profile to see the summary, and drill into specific events when you need to view additional details before acting on a domain, review its metadata, such as the whois contact and any mx records, to judge whether it represents a real threat exclude a legitimate lookalike domain if a detected lookalike domain is legitimate and you do not want to receive further updates about it, create a tenant scoped policy that excludes the domain and is restricted to the lookalike category this stops future updates for that domain across the tenant ignoring or remediating a single update event affects only that event it does not stop future updates for the domain