Scan for domain siblings

Prev Next

Domain siblings are domain names that share the same second-level domain name with a target domain, but have a different top-level domain (TLD). For example, if the target domain is example.com, its domain siblings might include example.net, example.org, and so on.

Domain siblings can be used in various ways, both legitimate and malicious. An organization may register multiple domain names that share the same second-level domain name to redirect traffic or protect its brand; however, threat actors may use domain siblings to impersonate a legitimate domain or website to deceive users and steal sensitive information.

Scan for siblings

  1. Navigate to Advanced Query Builder > Domain Queries > Siblings.

  2. Specify a domain.

  3. Click Search.

Save queries

Organizational users can save queries for future use or sharing.

  1. Specify query parameters.

  2. Click Save Query.

  3. Provide a Name and Description for context.

  4. Click Save. The query appears in Private Queries.

This protects against TLD variant attacks.