Domain Impersonation searches for domains that look like or target a hostname you enter. You do not start from an asset list. You start from a target domain. The feature then hunts for lookalikes of that name across typosquat, homoglyph, combosquat, and related patterns.
Enter the domain you want to protect, set a time frame, apply exclusions, choose how aggressive the lookalike logic should be, then click Submit to run a preview. That workflow matters when the brand is a single name, a campaign hostname, or a domain you are not yet tracking in My Assets.
If the inventory already lives in a My Assets folder, use Assets Impersonation instead. Domain Impersonation is the named-domain workflow. Assets Impersonation is the list-driven workflow.
Note
Domain Impersonation is the primary module and has been redesigned for simpler use with asset lists, scheduled monitoring, and background processing. The previous version is marked Legacy.
How the query form is structured
The Query Form is compact, but each control changes the quality of the candidate set. The required starting point is the target domain. From there, you narrow noise and decide how aggressive the lookalike logic should be.
Target domain: Required. Enter the brand or hostname to protect — for example,
example.comor the registrable label you care about.Time Frame: Scope the search window, for example, Last Week, so results stay relevant to recent registrations and activity.
Excluded Domains: Remove known-good or already-reviewed domains to avoid cluttering the candidate list.
Excluded Keywords: Filter out terms that generate false positives in your environment.
Typosquat Mode: Set to Strict when you want higher-confidence lookalikes and fewer speculative matches.
Include Digit Homoglyphs: Turn on to catch substitutions such as
0foroor1forl.Search On Subdomains: Expand the hunt beyond apex domains when attackers hide impersonation one level down.
Submit / Reset: Run a preview immediately, or clear the form and start over without leaving the page.
The practical sequence is simple: enter the target domain, set a time frame, apply exclusions, choose a typosquat mode, decide whether to include digit homoglyphs and subdomains, then submit. You can save the search later. You do not have to perfect monitoring settings before you see a preview.
How to read the results
After a search runs, the Results pane is not just a raw domain dump. It is organized so an analyst can decide what to investigate first.
Candidates
You see total matches, plus counts for the last 1 day, last 7 days, and IoFA where available. That split is the difference between “this lookalike has existed for years” and “this appeared in the last day and needs attention now.” New candidates and findings since the previous run are the primary focus once a search is saved and scheduled.
Impersonation Type Overview
Candidates are grouped by how they spoof you: typosquatting, homoglyphing, combosquatting, and more. That context tells you the attacker’s method, not just the string similarity. A combosquat that pairs your brand with login, secure, or support is a different problem than a single-character typo.
Typosquat: Misspelling of the brand domain, for example,
exampel.com.Homoglyph: Visually similar characters substituted, including lookalike Unicode.
Combosquat: Brand name combined with a suspicious or common word, for example,
example-login.com.TLD Concatenation: Brand and TLD combined so the full string spells the brand.
TLD Typosquat: Same brand label with a different or lookalike TLD, for example,
example.co.
Registration Date Overview
Freshly registered domains deserve a different response than aged infrastructure. Registration timing helps you separate opportunistic copycats from domains that may already be warmed up for use.
HTTP Response Overview
Not every lookalike is live. HTTP response context shows whether sites appear active. A parked or empty domain is still worth tracking; a live page that mimics your brand is an incident queue item.
Registrar Distribution and ASN Overview
Infrastructure context matters when you need to cluster related domains, identify a preferred registrar, or see whether candidates sit on the same network. One-off names are noise. Shared ASN and registrar patterns often point to a campaign.
Use these views to prioritize what to investigate first: recency, impersonation method, liveness, and infrastructure clustering, instead of working the list top to bottom.
Save once, monitor continuously
A one-off search finds what exists today. Impersonation does not stop after that snapshot. The Save action turns the query into an asset in its own right.
Click Save, give the search a name and optional description, then manage it from My Searches. From there you can:
Set a schedule so the search runs automatically.
Reopen the search with filters already filled in.
Share it with your organization, so brand protection is not confined to a single analyst’s session.
A clock icon on a saved search means it is scheduled. New results appear in the Notification Center and in My Searches, with a distinction between manual and scheduled runs. To stop monitoring, open the search and remove or edit the schedule.