Permutation strategies
Fuzzy Match Algorithms
Over a dozen fuzzy match algorithms are applied to identify potential impersonators for lookalike domains. To maintain high fidelity and reduce noise, the focus is on single-strategy permutations, with specific high-risk exceptions such as combining a typo with a TLD swap.
Strategy | Example | Description |
|---|---|---|
Addition | example1.com example2.com examplez.com | Add a letter to the end of the word |
Bitsquatting | exampme.com exampke.com exampie.com | What results when a single bit is flipped in the binary representation of a letter, often used for malicious purposes |
Hyphenation | e-xample.com ex-ample.com exam-ple.com | Insert a hyphen into various positions |
Insertion | exampmle.com exampqle.com exarmple.com | Insert an extra letter in the word |
Omission | exampel.com exmple.com | Remove a letter |
Plural | examples.com | Add an s to the end of the word to make it plural |
Repetition | examplee.com eexample.com exxample.com | Repeat one letter twice in the word |
Replacement | exampke.com exanple.com ezample.com | Replace a single letter with another letter in the alphabet |
Subdomain | ex.ample.com exam.ple.com | Split the original domain into a subdomain separated by . |
Transposition | exampl.com xeample.com | Move a letter one direction to the right inside the word |
Vowel-swap | eximple.com | Replace vowels with other vowels |
Homoglyph | exampIe.com exarnple.com | Replace letters with similar-looking characters from other alphabets |
Cyrillic | exampIe.com | Replace a letter with a nearly identical looking character from the Cyrillic alphabet |
Dictionary | example-login.com login-example.com examplelogin.com loginexample.com | Insert a word into the domain according to a dictionary (Suffix/Prefix with or without '-') |
TLD-swap | example.ca | Swap the original TLD (e.g., .com) with a different TLD (e.g., .ca) |
Subdomain Swap | example.pages.dev example1.pages.dev exampme.pages.dev e-xample.pages.dev examples.pages.dev exampel.pages.dev examplee.pages.dev exampke.pages.dev ex.ample.pages.dev eximple.pages.dev example-login.pages.dev loginexample.pages.dev | Use the original domain string (and various permutations) as a subdomain of a different root domain. |
Short Domain Logic
For domains of 3 characters or less (e.g., abc.com), the following strategies are excluded: Insertion, Omission, Replacement, Transposition, Plural, Addition, Bitsquatting, and Vowel Swaps. This prevents thousands of legitimate, unrelated three-letter businesses from being flagged.
Combosquatting with Dictionary Strategy (DNS Twist)
One of the most common tactics in phishing is the use of keywords appended to a domain name to create a sense of legitimacy or urgency. Rather than matching random character strings, the dictionary strategy checks a curated list of high-risk prefixes and suffixes that attackers use to manufacture legitimacy or urgency.
This helps identify social engineering domains designed to trick employees or customers into performing specific actions. The following terms are monitored: rh, hr, profile, login, account, portal, payments, admin, pages, corp.
Both prefix and suffix variations are caught, with or without a hyphen. The list is updated periodically based on emerging threat trends.
Formatting Variations
There are multiple variations of how these words are attached to your Identifier:
- Suffixes: example-login.com or examplelogin.com
- Prefixes: login-example.com or loginexample.com
If you would like a term to be added to the list please reach out to our Support team.
Subdomain Swapping and Platform Impersonation
In addition to traditional domain registrations, attackers frequently leverage legitimate Software as a Service (SaaS) and hosting platforms to host phishing pages, letting a lookalike ride on a trusted host's reputation. This is known as Subdomain Swapping.
Because these platforms often provide free SSL certificates and carry a high reputation, malicious subdomains can easily bypass basic email filters and look legitimate to the untrained eye.
Cloudflare Pages, *.pages.dev, is currently the only supported platform. It is a popular hosting site for phishing pages. The following permutation types are applied: Dictionary, Addition, Bitsquatting, Insertion, Omission, Plural, Repetition, Replacement, Transposition, and Vowel Swap.
Two design choices that reduce noise
Single-strategy focus. The focus is on single-strategy permutations rather than double permutations, so a domain combining both a character deletion and a dictionary addition typically will not match.
Short-domain exclusions. For domains of three characters or less, strategies like insertion, omission, and replacement are excluded, which would otherwise flag thousands of unrelated legitimate three-letter businesses.
Certstream-only Strategies
Some strategies are possible to use with Certstream only, since they would be prohibitively expensive to generate and check against DNSTwist. Because incoming certificates are received directly, these strategies can be compared against the incoming domain produce additional matches.
Strategy | Example | Description |
|---|---|---|
Starts With | example.com example-something.com | Similar to dictionary, but does not rely on a dictionary for the comparison. This only runs for domains of 4 characters or more. |
Ends With | example.com something-example.com | Similar to dictionary, but does not rely on a dictionary for the comparison. This only runs for domains of 4 characters or more. |