Brand Exposure Report
Enter your domain for an instant brand-exposure snapshot: whether your email can be spoofed, and which lookalike and typosquat domains are already registered against your brand — scored, with plain-English fixes. Reads public data only.
Live, read-only checks of public DNS and domain registrations. We don't store anything you enter.
Why new and growing brands get targeted
The moment a brand becomes recognizable, attackers start registering domains that look like it, to spoof its email, host fake login pages, or run scams against its customers. Two gaps make this easy: a domain that can be spoofed because it lacks an enforcing DMARC policy, and typosquat or lookalike domains that no one is watching. This report surfaces both in one pass.
What the report covers
Email spoofing. It looks up your DMARC and SPF records and grades whether spoofed mail using your domain would actually be rejected. A policy of p=none, common and easy to mistake for "set up", means it isn't.
Lookalike & typosquat domains. It generates the permutation patterns attackers use most: alternate TLDs (brand.co, brand.app), brand-plus-keyword combosquats (brand-login.com), homoglyphs and missing/transposed letters, and checks which are already registered. Any that can also receive mail are flagged, because that's how credential-phishing and business email compromise campaigns are staged.
From a snapshot to continuous protection
Running this once tells you where you stand today. Attackers register new lookalikes constantly, so the real job is continuous: monitoring new domain registrations and certificate transparency, detecting live impersonation, and taking it down. See how that works in brand protection and automated takedowns, or read the guide to detecting typosquatting domains.
Frequently asked questions
What does the Brand Exposure Report check?
Three things, from public data: whether your domain can be spoofed in email (your DMARC and SPF records), which lookalike and typosquat domains are already registered against your brand, and which of those lookalikes can receive email — a strong signal of an active phishing or credential-harvesting setup. It combines them into a single risk score.
How is the risk score calculated?
The score (0 = low exposure, 100 = critical) weighs the biggest real-world risks most heavily: a missing or monitoring-only DMARC policy lets attackers spoof your domain directly, so it adds the most points. Registered lookalike domains add more, and lookalikes that can receive mail add more still, because they're typically being used to phish your customers or staff.
A lookalike domain showed up that we own: is that a problem?
Not necessarily. Many brands defensively register common typos and alternate TLDs themselves, and those will appear here because the tool sees only that the domain is registered, not who owns it. Focus on the lookalikes you don't recognize — especially any marked mail-capable — and the email-spoofing gaps, which are always worth fixing.
Does this find every lookalike domain?
No. It checks a prioritized sample of the most common permutation patterns (alternate TLDs, brand-plus-keyword combosquats, character swaps and omissions) for fast results in your browser. A full program generates thousands of permutations across every TLD, monitors new registrations and certificate transparency logs continuously, and watches for live phishing pages. That's what PhishEye's brand protection does.
Is anything I enter stored?
No. Every check is a live, read-only DNS lookup over DNS-over-HTTPS: TXT records for your DMARC and SPF policies, then A and MX records for each lookalike candidate. The domain you enter isn't logged or saved.
Related free tools
See one snapshot. We watch continuously.
PhishEye monitors lookalike domains, fake sites, and impersonation across the web and takes them down, not one check at a time.
