Lookalike Domains Event Category
6 min
lookalike domains imitate your organization's real domains using tactics such as typosquatting, homoglyphs, and combosquatting they are a primary vector for phishing and brand impersonation these domains are monitored continuously across several detection sources detection covers newly issued ssl certificates, domains that resolve in dns, and domain intelligence from datapulse, with urlscan visual similarity detection added in the extended tier because dns based detection evaluates all currently registered domains rather than only new ones, lookalike domains that were registered long before you added your domain identifier are surfaced the lookalike domains event category covers every event generated for a domain imitating one of your domain identifiers these events appear in your events feed under the lookalike domains category lookalike domains in the events feed a lookalike domain typically moves through two stages it is first registered, and often sits dormant on a parking page it later becomes active, and its content and hosting infrastructure begin to change both stages are represented as separate events in the events feed new events a new event is generated the first time a lookalike domain is identified a domain identifiers these events come from multiple detection sources certstream monitors certificate transparency logs in real time and flags newly issued ssl certificates whose subject resembles one of your domain identifiers because this is a live stream, it does not return certificates issued before your identifier was created dnstwist generates permutations of your domain identifier and checks each one for active dns records it detects domains regardless of how long ago they were registered datapulse domain identifiers are also matched against intelligence from datapulse to surface domains it observes as possible lookalikes, extending coverage beyond permutation based and certificate based detection urlscan visual similarity detection from urlscan surfaces sites resembling your own, even when the domain name itself is not similar update events an update event is generated when a tracked attribute of a known lookalike domain changes, such as its ip address, page title, favicon, or screenshot because each change is its own event, you can get alerts docid\ eqfosnlszdt49 kdw6xts on lookalike domain changes as they happen each significant change to a known lookalike domain generates its own event with its own severity assessment, so a domain that was low priority as a parked page is re evaluated as soon as it begins to resemble your domain base tracking covers changes to a domain's ip address, page title, favicon, and screenshot with the extended tier, additional fields are tracked, including ssl certificates, dns records, and whois/rdap information how detection works lookalike domains are detected using the following methodology each pipeline runs on its own cadence, daily or weekly by strategy complexity certstream is the exception, running continuously against the live certificate stream for complete details on lookalike domain detection, including permutation strategies and scoring, see lookalike domains data source docid 5a9wixcgd5blfi9kdz6ii