Request demo

Brand Risk Protection

Find the Domains Built to Look Like You.

Brand Risk Protection matches new domains and subdomains against your brand keywords, including names spelled with letters from other alphabets that the eye cannot tell apart. Each lookalike your team confirms is then watched like an asset, so you see when it starts resolving, receiving mail or serving a certificate.

acme.example, and the addresses built to pass for it. A street with your shop and, beside it, what attackers build to pass for it: a lookalike domain with a copied login page and a mail exchanger, a confusable twin, a search ad, a fake app and a fake support account, then the takedown.
  1. Your shop, acme.example, in ink.
  2. Lookalike domain: acme-login.example, caught by a contains rule.
  3. Phishing page: in its window a copy of your login; it answers HTTP and serves a certificate.
  4. Mail exchanger: its MX record is on, so it can send and receive mail: phishing.
  5. Confusable name: аcme.example, its first letter a Cyrillic “а”.
  6. Search engines: an ad, “Acme Support, 24/7 help”, leads to a login page on acrne-support.example.
  7. App stores: “Acme Support”, a listing whose publisher is not you.
  8. Social media: “support” agent, posing as your support team.
  9. Managed Takedown: confirmed by your team, filed with the registrar and the host; the next scan finds http, ssl, dns_mx and dns off.

A Convincing Phishing Page Needs a Convincing Address.

An impersonation campaign needs a domain before it needs a phishing kit or a mailing list. Registering one is cheap, and the name can look exactly like yours.

Registration

Any Name, on Almost Any TLD

Your brand plus “login”, your name with one letter doubled, your exact name on a new extension. Each one is a separate registration that anyone can make.

Rendering

Letters the Eye Can’t Separate

A Cyrillic “а” and a Latin “a” look the same in most fonts. In an email or a chat message, an internationalized name can read as yours while DNS resolves an xn-- name underneath.

Preparation

Setup Leaves Traces

To host a login page a lookalike needs DNS records and usually a certificate. To send or receive mail it needs a mail exchanger, and each of those shows up in data the Deepinfo Platform already collects.

Match Types That Catch What a Typo Filter Misses.

Each rule pairs a brand keyword with one match type. Below, one name and what four of the types would catch: the confusable types add the substitutions a typo filter never checks.

  1. acme.example

    Your keyword

    Each rule pairs it with one match type

  2. acme.test

    Same name · exact

    The name itself, on another TLD

  3. acrne.example, r + n for m

    Typo · fuzzy

    One edit away: a dropped, doubled, swapped or mistyped letter

  4. аcme.example, U+0430 CYRILLIC SMALL LETTER A

    resolves as xn--cme-5cd.example

    Lookalike letters · confusable_exact

    Letters swapped for ones that look identical

  5. aсem.example, swapped “me” · U+0441 CYRILLIC SMALL LETTER ES

    resolves as xn--aem-4ed.example

    Lookalike and typo · confusable_fuzzy

    A typo and a lookalike letter together

From a Keyword to a Monitored Lookalike.

  1. 01

    Rule

    Pick a brand keyword and a match type, then narrow the rule: domains or subdomains, extensions to include or exclude, words that discard a match.

  2. 02

    Match

    The rule runs against new domains and subdomains as they enter Deepinfo’s index. With include_past on, it also checks names registered before the rule existed.

  3. 03

    Review

    Matches arrive as suspicious domains, each with the rule that found it. Your team approves or ignores them one by one or in bulk, and can revert either decision. A rule you trust can approve its own matches.

  4. 04

    Monitor

    An approved match becomes a fraudulent domain. The platform tracks whether it resolves, receives mail, serves a certificate or answers HTTP, and keeps its DNS, SSL, WHOIS, web data and port history.

  5. 05

    Act

    File with the collected evidence yourself, or hand the case to Managed Takedown. A notification rule on new_fraudulent_domain_detected emails your team instantly or in an hourly to monthly digest.

What Each Lookalike Carries With It.

A match is not a verdict. Each record keeps what your team needs to decide, and the history to support a takedown request or a dispute later. These records also come back from the BRP API, under the platform’s apikey header.

Namefraudulent and fraudulent_unicode: the name as registered, in xn-- form for internationalized names, and the name as a browser displays it
Typefraudulent_type: domain or subdomain
Detectionsdetection_history: the rules that matched the name, and when
Statestate: in_review, approved or ignored, with the date of each decision
Indicatorsmonitoring_indicator: the flags dns, dns_mx, ssl and http, for whether the name resolves, receives mail, serves a certificate and answers on the web
Login pageis_login_page and screenshot: whether the lookalike serves a login page, and a capture of the page itself
Risk scorerisk_score: the current score, plus a timeline of how it has moved
HistoryDNS, SSL, WHOIS, web data and port scan history for each monitored lookalike

Questions About Brand Risk Protection

What is Brand Risk Protection?

Brand Risk Protection is the detection and removal of infrastructure that impersonates your organization: lookalike domains, the pages and mail servers built on them, and impersonation on social platforms, app stores and search engines. It treats brand abuse as something to watch continuously, not something customers report to you after the fact.

Which channels does BRP cover?

Domains and subdomains, through Fraudulent Domain Monitoring, and impersonation on social platforms, app stores and search engines, where coverage is confirmed per engagement. Confirmed findings from each channel can go to Managed Takedown.

How is this different from a list of typo variants?

A static list covers the names someone thought of in advance. BRP matches rules against domains as they appear, includes confusable characters, and keeps watching every confirmed lookalike, so your team sees when a parked name gets a mail exchanger, a certificate or a live web page.

Is every match a phishing domain?

No. Resellers, fan sites and names parked years ago match too, which is why matches wait for your team’s review and the monitoring indicators show which ones are being put to work.

Will our own and our partners’ domains be flagged?

Not if they are on the ignore list: domains you add to it in the BRP settings are never reported.

What does the takedown workflow look like?

Your team reviews a suspicious domain and approves it, which starts monitoring. When it turns abusive, you can file using the DNS, SSL, WHOIS and web evidence the platform has collected, or hand the case to Managed Takedown, where Deepinfo’s team files with the registrar or hosting provider and follows each request to a close.

How is BRP priced?

Pricing depends on the scope you monitor. See pricing for how it works, or talk to us for a scoped quote.

See Who’s Pretending to Be Your Brand.

Book a working demo with rules built on your brand names.