a watched domain’s DNS, mail, and certificate on the record as they change, so the evidence exists before the site rotates its infrastructure and a screenshot would go stale.
For Brand & Fraud · Faster Takedowns, Evidence That Holds
The lookalike,
caught on the record.
878,111 lookalike domains were registered to attack brands in 2024 (Interisle). The return: a takedown that lands faster, on a dated record captured while the site was live. Honest status: reliable attack-time capture of a brand-new lookalike lands as the fast-scan lane ships.
One working artifact: the signed evidence report.
Every reading DomainDrift takes is signed the moment it is observed and travels as a dated evidence report you can hand over: state, providers, registrar, expiry, email authentication, DNSSEC and subdomains, per domain, on one page. The recipient re-checks every reading themselves in the public verifier, with no account, years later. That artifact is the same on every page here. The persona only changes which part of it you foreground, on the same $10 / $29 / $99 ladder.
The math, before the feature.
The return is a takedown that lands faster and holds when the case escalates. With roughly 989,000 phishing attacks in Q4 2024 alone (APWG), the hard part is rarely spotting the lookalike; it is proving what it was after its DNS and certificate have moved. DomainDrift watches the domains you name and keeps a dated, signed record of each one as it changes, so what the site looked like while it was live is already on file when you file the report.
every record is dated and checkable, so the abuse report, the ICANN complaint, and the court filing rest on evidence the registrar cannot wave off as a doctored image.
for a domain already under watch, changes are captured today. Reliable capture of a brand-new lookalike the moment it goes live lands as the fast-scan lane ships. We frame it as coming, not as live.
Capture the lookalike before its infrastructure rotates.
A lookalike of your domain goes live, harvesting customer logins. You screenshot it.
The registrar asks for proof. The site has already rotated its DNS and swapped its certificate; your screenshot is stale.
Because the domain was under watch, DomainDrift already kept a dated record of its DNS, mail, and certificate from while it was live. The takedown, the ICANN complaint, and the court filing hold.
The genuine brand, on the record
The product, pointed at your desk.
The real brand, on the record
Protection starts from the genuine brand itself, read from the outside and put on the record, so you have a baseline to measure a lookalike against: the real brand’s IPs, mail, and certificate, plus who is allowed to send email as it. A fraudulent copy gives itself away by how far its record drifts from the genuine one. The genuine domain is the yardstick, never the fraud.
A copy is caught by how far its record drifts from the genuine brand’s reading.
Watch the marks, hear the change
Group your marks and known lookalikes and get told the moment one changes, over a signed webhook. Every record is dated and checkable, so what a watched site looked like while it was live is already on file, and a registrar or a court can open and verify it in their own browser after the site is gone.
The honest status, said plainly
For a domain already under watch, changes are captured today. The fast lane that makes capture of a brand-new lookalike reliable the moment it goes live is in progress; we frame it as coming, not as live. A dated reading kept while a site was live can be added to, never recreated after the site rotates.
Read any domain from the outside, dated and signed, with no account.
Group your marks and known lookalikes; a free account watches one, paid plans the watchlist.
Pull a domain’s dated record as a bundle a registrar or a court can open and verify.
A dated record of the malicious site’s DNS, mail, and certificate, kept from while it was live, that still holds when the registrar, ICANN, or a court asks for proof. Reliable capture of a brand-new lookalike the moment it goes live lands as the fast-scan lane ships.
An independent, signed record, now anchored to Base
Every reading is signed the moment it is taken and chained to the one before, against published keys, and each day's readings are rolled into a single root and anchored to Base, a public chain, so the date is confirmed by the chain and not only by us. That proves who took each reading, that nobody has altered it since, and when it was taken. It is attribution, integrity, and an independent timestamp, never a claim the reading is correct: a signature can sit on a wrong observation. Anyone re-checks any reading themselves at the verifier, no account, years later. The signature is the first-mover trust layer; the lasting advantage is the dated record itself, which compounds and cannot be recreated after a domain changes, or rewritten once it is anchored.
Start free
A free account puts one of your own domains under watch, keeps its history, and sends a signed alert the moment we see it change. Paid plans raise the dials; pricing is on its own page.
Free to start. No credit card. Your signed record is yours to keep and verify anywhere.