DomainDrift for brand and impersonation defense

Catch a lookalike domain before it arms.

A typosquat of your brand can sit parked and quiet until the day it stands up a mail server and a fresh certificate, the setup a phishing run needs. Name the lookalikes you worry about, resolving or not, and DomainDrift watches each one from before it answers. The switch-on lands as a dated, signed event, and the reading from before it resolved is the baseline that proves it.

Lookalike domains, watched from before they resolve

Brand impersonation and typosquats start as a name that answers nothing. A name that answers nothing is still a reading.

  1. Name it. Add a lookalike to a watch group. Registered or not, resolving or not. The first signed reading lands in seconds; the five-minute watch lane runs under it from there.
  2. The reading before. A resolver answering NXDOMAIN has answered. That answer is signed and dated like any other reading, and it is the baseline.
  3. The reading after. The day the name starts answering, the change lands as a dated event: the empty side before, the nameservers, mail exchangers and certificate after. The alert carries the same event.

Takedown work wants an exhibit, not a screenshot. Both readings export as a dated evidence report, and the registrar or host who receives it re-checks every signature in the public verifier, offline, with no account. A signature proves who took a reading and that it has not been altered since. It does not make the reading correct.

Scope, plainly: DomainDrift reads a curated catalog plus the domains you name. It does not enumerate every lookalike of a brand, and it does not judge whether a site is phishing. It records what each name published, and when.

Two steps in

1 · Try it, no account
curl https://domaindrift.io/v1/domains/example.com

One keyless request every 15 seconds per IP, for any domain in the catalog. It returns a reduced preview record with a receipt pointer you can resolve right away.

2 · Register

Opens the complete signed record and every list in full, and puts one of your own domains under watch. 20 API requests a day, refreshed at midnight UTC.

Pro puts your whole watchlist of lookalikes on the five-minute lane and sends webhook alerts your team can route the moment one arms.

Create an account →

What it costs →

CONTINUOUS INTERNET TELEMETRY24H DRIFT25,159 material changesacross 19,886 domains · 24h to ~80m agoROTATION56 domains moved DNS from koaladns.com to magpiedns.com, 53 moved backa rotation loop, not a migration · 24hCERT DRIFT1 domains switched issuing CA24hREGISTRAR DRIFT3 changed registrar24hNOW563 curated domains not reachablelast probe, steadySITE ERRORS18,202 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 80,870 sites429 rate-limit / 403 bot-block, a posture signal