Look-alike domains: which ones matter
The finder generates up to 140 variants of your name from the patterns attackers actually use: a dropped letter, a doubled one, two swapped, a keyboard neighbour, a hyphen, a homoglyph such as rn for m, a suffix like -login, and the same name under another top-level domain. It then resolves each one to see which exist.
A domain that resolves is not proof of abuse. Some are parked by speculators, some are registered defensively by the brand itself. The ones to act on first are the variants that also carry an MX record: they can receive mail, which is what a phishing campaign needs to look credible.
Practical order: register the three or four cheapest high-risk variants yourself, add the rest to a monitoring list, and make sure DMARC on the real domain is at reject so the look-alikes cannot borrow your name in the From line.
Run the lab: Typosquat finder →
A lab shows one signal. The call checks the whole chain.
Book a 30-minute call