A new phishing site goes live
every 8 seconds.
Source: APWG, 2025. Nearly every one starts with a domain
registered to impersonate a real brand.
how it works
Detect, score, take down.
The same three-step pipeline behind every takedown, from the
moment a domain is registered to the moment it is removed.
01 · Detect
We watch every new registration.
Newly registered domains across watched TLDs are fingerprinted hourly. Brand-keyword permutations build the watchlist, and fresh registrations cross-match in seconds.
Hourly sweep of new registrations
Brand-keyword permutation engine
Typo, homoglyph and TLD variants
Same-day detection on watched terms
02 · Score
We rank what is actually a threat.
An intent classifier scores each match on the signals that matter: website copy, live nameservers, a cloned favicon, configured MX records, payment-related keywords in the path.
Severity scored, not just flagged
Live nameserver and MX checks
Favicon and visual similarity match
Website copy compared
03 · AI AGEnt Takedown
We file and track the removal.
AI agents compile the full evidence pack - WHOIS, screenshots, certificate fingerprint and similarity score - then file it with the registrar and host.
Evidence pack assembled for you
Filed with registrar, host and Nominet
Removal tracked end to end
No manual chasing from your team

Scenario
their-brand-offers.co.uk
4:33 hr takedown
From registration to takedown - before a single customer searched.
A 200-employee homeware retail brand. At 09:14 someone registers their-brand-offers.co.uk By 09:47, DomainGuard has already fingerprinted the site: live nameservers, a cloned favicon matched 94% to the brand's CDN, payment-related keywords in the path, MX records configured & 80% copy matched.
CyberProtect scores the registration at 87 - high impersonation intent. A finding card opens with the evidence pack pre-built: WHOIS snapshot, full-page screenshot, certificate fingerprint, similarity score, and the registrar's specific takedown form.
One click files with the registrar plus Nominet DRS as a backstop. Takedown filed by 11:42 - before a single customer search sees the lookalike.
Outcome
33 min
from registration to detection
1 click
to file takedown
0
customer clicks before takedown
Filed
registrar + Nominet DRS
What we monitor
Six channels. One pane of glass
Typosquats & homoglyphs
Look-alike spellings and mixed-script characters scored by impersonation intent.
Every TLD that matters
.com, .co.uk, .shop, .store, .online and the new TLDs as registrars launch them.
Cloned visual assets
Pixel-similarity matches cloned logos, favicons, and product images before conversion.
Marketplace impersonation
Listings copying your brand on Amazon, eBay, Etsy and TikTok Shop, without your licence.
App-store knock-offs
Look-alike apps on the App Store, Google Play and third-party APK aggregators.
Paid-ad hijacking
Competitors and impostors bidding on your brand keywords across Google and Meta ads.
The hard questions, answered straight.
How fast does a lookalike domain actually get taken down?
Do you monitor domains we don't own — partner sites, resellers, franchises?
How do you tell a legitimate marketing domain from a malicious lookalike?
Is takedown automatic, or do we approve each one?
What evidence goes into the takedown request?
Do you track certificate transparency logs, or just DNS registrations?









