Lookalike Domains Data Source
13 min
lookalike domains are a primary vector for phishing and impersonation flare's automated monitoring detects these domains as they are registered, as they are issued an ssl certificate, and as they begin to resemble your own sites visually detection methodology four discovery sources are used together to provide coverage across the web real time certificate transparency through certstream certificate transparency logs are monitored in real time whenever a new ssl certificate is issued by a public certificate authority https //certificate transparency dev/ , the domain name is analyzed against your protected identifiers this catches malicious sites at the moment they are being prepared for https traffic strength detects malicious sites the moment they are prepared for https traffic limitation because this is a live stream, it does not provide historical data for certificates issued before your identifier was created domain fuzzing through dnstwist thousands of permutations of your domain are generated proactively and active dns records are checked this surfaces domains that were registered months or years before you started using flare checks run on a rolling daily or weekly basis depending on the permutation strategy over a dozen fuzzy match algorithms are applied to generate permutations these include addition, bitsquatting, hyphenation, insertion, omission, plural, repetition, replacement, subdomain splitting, transposition, vowel swap, homoglyph, cyrillic substitution, dictionary terms, and tld swap additionally, monitoring covers more than 80 of the most common and high risk top level domains, including country codes such as com, net, io, app, ca, uk, and ru strength identifies domains that were registered months or years before you joined flare frequency checks are performed on a rolling basis (daily or weekly depending on the permutation strategy) permutation strategies many different techniques are used to find possible lookalike domains through certstream and dnstwist discovery for the full list, see permutation strategies for lookalike domains docid\ muyce xeeib4aeyb xzqv domain intelligence through datapulse your domain identifiers are matched against intelligence from datapulse, which extends coverage beyond permutation based and certificate based detection strength surfaces domains observed through registrar and domain intelligence rather than generated permutations visual similarity through urlscan visual similarity detection from urlscan surfaces sites resembling yours even when the domain name itself is not similar this catches impersonation that name based detection alone would miss strength catches impersonation that name based and certificate based detection alone would miss important considerations identifier exclusions if you own example com and example ca and have added both as identifiers, flare will not alert you on one being a lookalike of the other combination limits to ensure high performance and low false positive rates, double permutations are not typically detected, for example a domain that uses both a character deletion and a dictionary addition specific high risk combinations, such as a typo paired with a tld swap, are an exception supported tlds flare monitors over 80 of the most common and high risk top level domains, including com , net , io , app , and various country codes like ca , uk , and ru tld coverage and exceptions ph domains behave differently from other tlds and can produce unexpected lookalike results for details on why this happens and how to respond, read our playbook https //docs flare io/respond to ph domain alerts#why ph domains behave differently to check whether a specific tld is monitored, contact flare support lookalike domain events lookalike domains generate two kinds of events new events are generated the first time a lookalike domain is identified for one of your domain identifiers update events are generated when a tracked attribute of a known lookalike domain changes, such as its ip address, page title, favicon, or screenshot with the extended tier, additional fields are tracked, including ssl certificates, dns records, epp status, registrar and registrant information, and mx records because each change generates its own event, you can set up alerts on lookalike domain changes as they happen for full details, see lookalike domains event category docid\ uzcbevxesd6p0odnylec3 identifier matching the following rules apply when matching lookalike domains on your identifiers if you have two domain identifiers abc ca and aabc ca , lookalike domain events will not be created for abc ca or aabc ca , even though they are both lookalikes of each other note that if the aabc ca domain identifier is added after a lookalike event has already been added to the feed of abc ca , the event is not removed from the feed certstream only detects newly registered domains in real time, and no historical data is available from this source matches from certstream on new domains cannot be backfilled dnstwist will detect domains that are currently registered, no matter how long ago it was first registered however, if a domain was registered in the past, then expired and is no longer registered, dnstwist will not pick it up scoring the default severity score for most ssl certificate registrations found is low however, multiple factors enter into the risk classification algorithm, possibly pushing the risk score either way low severity factors leading to lower scores include whether the domain registered is suspected to belong to you, looking among other things at the domain and tld in the case of a subdomain registration various trustworthy cloud and hosting services automatically register domains that follow a specific pattern high severity factors leading to a higher severity score include the registration authority, the similarity between domains, and how many domains were registered at once severity is re evaluated on every observation rather than set once at discovery a domain that was low priority as a parked page is re assessed as soon as it begins to resemble your own site, so its severity can rise or fall over time related articles