Short answer: Enter your domain and the checker builds the look-alikes a phisher would register: a missing, doubled or swapped letter, a neighbouring key, characters that look alike such as rn for m or 0 for o, an added hyphen or word, and the same name under other TLDs. It asks public DNS which of them exist and shows their A and MX records. A look-alike with MX records can receive mail, so it is the one to watch.
We tested the checker on 7 October 2026 against live DNS. For paypal.com it built 64 variants and found 51 registered, 26 of them with mail servers (a mix of PayPal’s own defensive registrations, parked domains and unrelated businesses). For srvscripts.com it built 97 variants and found one registered look-alike with a mail server.
Table of Contents
How to read the result
- Registered look-alikes are names that exist in DNS (they have name servers or an A record). Most popular brands have dozens; many are registered by the brand itself to keep them away from others.
- Can receive mail (MX) marks look-alikes with MX records. Replies to a phishing mail sent “from” such a domain reach whoever controls it, and it can also send mail that passes its own SPF and DKIM.
- How it differs names the trick: missing letter, doubled letter, swapped letters, neighbouring key, look-alike character or letters, added hyphen, added word or other TLD.
- A dash in the A record column means the name has DNS but no web server address; “no mail” means no MX or a null MX that refuses mail.
What to do about a look-alike
- Check who owns it with the WHOIS lookup. Your own company, a registrar’s parking service or an unrelated business with a similar name are all common and harmless.
- If a look-alike impersonates you (copies your website, logo or mail), collect evidence: screenshots, full headers of any mail (paste them into our email header analyzer) and the DNS records from this check.
- Report it to the registrar’s abuse contact and to the hosting or mail provider shown in the A and MX records. Most registrars act faster on phishing reports that include headers.
- Protect your real domain: publish SPF, DKIM and DMARC with
p=rejectso nobody can send mail as your exact domain. Check yours with the DMARC checker. - Consider registering the closest typo variants yourself, especially the missing-letter and swapped-letter ones of short names, and point them at your main site.
What it checks and what it does not
The checker only queries public DNS for each candidate name (NS, A and MX). It does not visit the websites, does not send mail and does not use registrar data, so it cannot tell you who registered a domain or when. To keep each run fast it checks up to 160 candidates, typo variants first. Internationalised (Unicode) look-alikes such as Cyrillic letters are not generated yet; those need registrar-level monitoring. Because DNS can change at any time, run the check again before you act on a result.
Common problems
- Your own defensive domains show up. That is expected; the checker cannot tell your registrations from someone else’s. Keep a list of the ones you own.
- “The name part is too short”. Names with fewer than three characters before the TLD produce too many unrelated real words to be useful.
- A look-alike has MX but you see no mail from it. Many parking services publish catch-all MX records. Treat it as a risk to watch, not as proof of an attack.
Official documentation: RFC 7505: A “Null MX” No Service Resource Record · ICANN: Report domain name abuse · APWG: Report phishing
Related: DMARC Checker · WHOIS Lookup: Free RDAP Domain and IP Owner Check · Email Header Analyzer · SPF, DKIM and DMARC in cPanel DNS: Setup and Checks
Frequently asked questions
What is a lookalike domain?
A domain registered to look like a real one at a glance, for example with a missing letter, rn instead of m, or another TLD, usually to trick people into trusting a phishing site or mail.
Is every registered look-alike malicious?
No. Many are defensive registrations by the brand, parked domains or unrelated businesses. Check the WHOIS owner and what the domain actually does before you act.
Why does MX matter?
A look-alike with MX records can receive replies to phishing mail and usually send mail that passes its own SPF and DKIM, so it is the most useful kind for an attacker.
Does DMARC stop lookalike domains?
No. DMARC protects your exact domain from being spoofed. A look-alike is a different domain with its own records, so it has to be reported or registered by you.
Do you check Unicode look-alikes?
Not yet. The checker builds ASCII variants only; Unicode (IDN) homographs need separate monitoring.