Brand Risk Protection
Find the Domains Built to Look Like You.
Brand Risk Protection matches new domains and subdomains against your brand keywords, including names spelled with letters from other alphabets that the eye cannot tell apart. Each lookalike your team confirms is then watched like an asset, so you see when it starts resolving, receiving mail or serving a certificate.
- Your shop, acme.example, in ink.
- Lookalike domain: acme-login.example, caught by a contains rule.
- Phishing page: in its window a copy of your login; it answers HTTP and serves a certificate.
- Mail exchanger: its MX record is on, so it can send and receive mail: phishing.
- Confusable name: аcme.example, its first letter a Cyrillic “а”.
- Search engines: an ad, “Acme Support, 24/7 help”, leads to a login page on acrne-support.example.
- App stores: “Acme Support”, a listing whose publisher is not you.
- Social media: “support” agent, posing as your support team.
- Managed Takedown: confirmed by your team, filed with the registrar and the host; the next scan finds http, ssl, dns_mx and dns off.
A Convincing Phishing Page Needs a Convincing Address.
An impersonation campaign needs a domain before it needs a phishing kit or a mailing list. Registering one is cheap, and the name can look exactly like yours.
Registration
Any Name, on Almost Any TLD
Your brand plus “login”, your name with one letter doubled, your exact name on a new extension. Each one is a separate registration that anyone can make.
Rendering
Letters the Eye Can’t Separate
A Cyrillic “а” and a Latin “a” look the same in most fonts. In an email or a chat message, an internationalized name can read as yours while DNS resolves an xn-- name underneath.
Preparation
Setup Leaves Traces
To host a login page a lookalike needs DNS records and usually a certificate. To send or receive mail it needs a mail exchanger, and each of those shows up in data the Deepinfo Platform already collects.
One Watch From Lookalike to Takedown.
Fraudulent Domain Monitoring does the matching and the watching on domains. Social media, app store and search engine monitoring cover where customers meet your brand away from your domains, and Managed Takedown handles removal.
Fraudulent Domain Monitoring
Rules match new domains and subdomains against your brand keywords, from exact names to typos and confusable letters. Confirmed lookalikes are monitored for DNS, MX, SSL and HTTP activity, with a risk score kept as a timeline.
Social Media Monitoring
Accounts on social platforms that present themselves as your brand or as one of its official channels.
App Store Monitoring
Apps listed in app stores under your brand name that your organization did not publish.
Search Engine Monitoring
Results on search engines that use your brand to send people somewhere you don’t control.
Managed Takedown
When your team confirms a lookalike is abusive, Deepinfo’s takedown team files the removal requests and follows each one to a close.
Match Types That Catch What a Typo Filter Misses.
Each rule pairs a brand keyword with one match type. Below, one name and what four of the types would catch: the confusable types add the substitutions a typo filter never checks.
-
acme.example
-
acme.test
-
acrne.example, r + n for m
-
аcme.example, U+0430 CYRILLIC SMALL LETTER A
resolves as xn--cme-5cd.example
-
aсem.example, swapped “me” · U+0441 CYRILLIC SMALL LETTER ES
resolves as xn--aem-4ed.example
From a Keyword to a Monitored Lookalike.
-
01
Rule
Pick a brand keyword and a match type, then narrow the rule: domains or subdomains, extensions to include or exclude, words that discard a match.
-
02
Match
The rule runs against new domains and subdomains as they enter Deepinfo’s index. With
include_on, it also checks names registered before the rule existed.past -
03
Review
Matches arrive as suspicious domains, each with the rule that found it. Your team approves or ignores them one by one or in bulk, and can revert either decision. A rule you trust can approve its own matches.
-
04
Monitor
An approved match becomes a fraudulent domain. The platform tracks whether it resolves, receives mail, serves a certificate or answers HTTP, and keeps its DNS, SSL, WHOIS, web data and port history.
-
05
Act
File with the collected evidence yourself, or hand the case to Managed Takedown. A notification rule on
new_emails your team instantly or in an hourly to monthly digest.fraudulent_ domain_ detected
What Each Lookalike Carries With It.
A match is not a verdict. Each record keeps what your team needs to decide, and the history to support a takedown request or a dispute later. These records also come back from the BRP API, under the platform’s apikey header.
| Name | fraudulent and fraudulent_: the name as registered, in xn-- form for internationalized names, and the name as a browser displays it |
|---|---|
| Type | fraudulent_: domain or subdomain |
| Detections | detection_: the rules that matched the name, and when |
| State | state: in_, approved or ignored, with the date of each decision |
| Indicators | monitoring_: the flags dns, dns_, ssl and http, for whether the name resolves, receives mail, serves a certificate and answers on the web |
| Login page | is_ and screenshot: whether the lookalike serves a login page, and a capture of the page itself |
| Risk score | risk_: the current score, plus a timeline of how it has moved |
| History | DNS, SSL, WHOIS, web data and port scan history for each monitored lookalike |
Query This Data Through the API
Lookalike matching runs over the domains the index sees each day. Data teams can take these domains as a feed and run their own matching. The index holds 400M+ domains, 2B+ subdomains, 200B+ DNS records and 30B+ SSL certificates.
Questions About Brand Risk Protection
What is Brand Risk Protection?
Brand Risk Protection is the detection and removal of infrastructure that impersonates your organization: lookalike domains, the pages and mail servers built on them, and impersonation on social platforms, app stores and search engines. It treats brand abuse as something to watch continuously, not something customers report to you after the fact.
Which channels does BRP cover?
Domains and subdomains, through Fraudulent Domain Monitoring, and impersonation on social platforms, app stores and search engines, where coverage is confirmed per engagement. Confirmed findings from each channel can go to Managed Takedown.
How is this different from a list of typo variants?
A static list covers the names someone thought of in advance. BRP matches rules against domains as they appear, includes confusable characters, and keeps watching every confirmed lookalike, so your team sees when a parked name gets a mail exchanger, a certificate or a live web page.
Is every match a phishing domain?
No. Resellers, fan sites and names parked years ago match too, which is why matches wait for your team’s review and the monitoring indicators show which ones are being put to work.
Will our own and our partners’ domains be flagged?
Not if they are on the ignore list: domains you add to it in the BRP settings are never reported.
What does the takedown workflow look like?
Your team reviews a suspicious domain and approves it, which starts monitoring. When it turns abusive, you can file using the DNS, SSL, WHOIS and web evidence the platform has collected, or hand the case to Managed Takedown, where Deepinfo’s team files with the registrar or hosting provider and follows each request to a close.
How is BRP priced?
Pricing depends on the scope you monitor. See pricing for how it works, or talk to us for a scoped quote.
See Who’s Pretending to Be Your Brand.
Book a working demo with rules built on your brand names.