Lookalike domain scanner

Domain squatting is somebody registering a name that reads like yours in order to profit from it. Type your domain. The scan bends the name ten different ways, checks each version against up to fourteen other endings, and tells you what is standing on the ones that are taken.

Verified August 21, 2026

What comes back

  • Every lookalike name that is taken, sorted by what is actually running on it.
  • A flag on any live hit serving the same icon file your own site serves.
  • The permutation category behind each hit, so you can see which kind of mistake it catches.
  • A page you can send to a lawyer or a co-founder as-is.

Names are shown as plain text. Some of these hosts serve a fake checkout, so nothing here is clickable.

Result

Enter your domain

Every name the scan generates lands in one of seven answers.

  • Live Shopify store. A Shopify storefront is answering on this name.
  • Frozen Shopify store. Shopify is not serving this store right now, which is what a store shut off for non-payment looks like from outside.
  • Resolves to something else. Something is answering on this name and it is not a Shopify storefront.
  • Resolves, not classified. This name points at an address. We did not get an answer about what is running there, or the scan reached its check limit before this row.
  • Registered, no site. This name has nameservers and nothing serving a page. Somebody holds it.
  • We could not check. The lookup did not complete for this name. That tells you nothing about it either way.
  • No DNS answer. Nothing answered for this name. Likely unregistered. Only a registrar search confirms availability.

The scan runs on its own page and takes a minute or two. The link stays good, so you can come back to it.

What is domain squatting?

Domain squatting, also called cybersquatting, is registering a domain name in order to profit from somebody else's brand. US law puts a definition on it. The Anticybersquatting Consumer Protection Act, signed on November 29, 1999 as part of Public Law 106-113 and sitting in the Lanham Act at 15 U.S.C. section 1125(d), makes you liable when you register, traffic in or use a domain name that is identical or confusingly similar to a mark that was distinctive at the time you registered it, and you did it with a bad-faith intent to profit from that mark.

Both halves have to be there. The name has to read like the mark, and the intent has to be bad faith. That second half is why the same parked page can be lawful on one name and unlawful on another. Registering a generic word nobody holds a mark in and selling it later is a business. Registering a misspelling of a brand and waiting for the brand to buy it is the thing the statute names.

The dispute policy every generic top-level domain is bound by says the same thing in its own words. Registering a name primarily to sell it to the mark owner or a competitor for more than your out-of-pocket costs is listed in the UDRP as evidence of bad faith. So a for-sale page on a name that spells your brand wrong is not a neutral fact. It is one of the named signals.

The board this is played on keeps getting bigger. IANA listed 1,438 endings delegated in the DNS root zone on August 20, 2026, counting the country codes and the generic ones together. Your name can be registered again on every one of them.

The ten kinds of lookalike domain, with examples

The scan above runs exactly these ten categories and no others, and seeing them side by side tells you which ones you are exposed to. Here is every category applied to one made-up brand, northpine.com.

Missing letter

Doubled letter

Swapped letters

Neighboring key

Different vowel

Hyphen added or dropped

Plural form

Lookalike characters

Word bolted on

Different ending

Ten categories, run against your name and against fourteen other endings. The table below works every one of them on a single example.

Category What changes northpine.com becomes
Missing letter One character dropped nothpine.com
Doubled letter One character typed twice northppine.com
Swapped letters Two neighboring characters traded nortphine.com
Neighboring key A character replaced by the key next to it morthpine.com
Different vowel One vowel replaced by another northpune.com
Hyphen added or dropped A hyphen pushed in, or an existing one removed north-pine.com
Plural form An s added or taken off the end northpines.com
Lookalike characters Characters that read as each other in most type n0rthpine.com
Word bolted on shop, store, outlet, official, sale or us, front or back shopnorthpine.com
Different ending The same name on one of up to fourteen other endings northpine.shop

The lookalike-character row is the one worth a second look, because it is the only category where the reader is being fooled rather than the typist. Pairs like rn and m, cl and d, and the digits 0 and 1 against the letters o and l are hard to separate in a small sans-serif font in a browser address bar.

There is a harder version of that trick this scan does not cover. Unicode contains strings that are always rendered as the same sequence of glyphs even though the characters differ, so a Cyrillic letter can stand in for a Latin one and produce a name that is visually identical rather than merely close. The Unicode Consortium's own security report uses a Cyrillic c inside citibank as the example. Those names are registered in punycode and are a different search than the one above; treat this scan as the ASCII half of the problem.

The idea of generating permutations and resolving them is not ours. dnstwist, the open-source domain name permutation engine by Marcin Ulikowski, has done it under an Apache 2.0 license for years and is where a lot of this thinking starts. What it hands back is raw DNS records, and reading those is a job. The scan above sorts the same kind of output into what a store owner has to do about each row.

Registered is not the same as dangerous

Run any brand name through a permutation scan and a pile of the results come back taken. That number on its own is close to meaningless. Common English words get registered by investors, short names get registered by everybody, and a name held by a parking service for eleven years has nothing to do with you. What matters is what is standing on the name today.

Live Shopify store

Frozen Shopify store

Resolves to something else

Resolves, not classified

Registered, no site

We could not check

No DNS answer

The last two are absences, not findings. A lookup that did not complete is not the same as a name nothing answered for, and neither one means the name is free.

The top tier is the one to act on. A lookalike name serving a live storefront, and especially one serving the same icon file your own site serves, is somebody who built a copy rather than somebody who bought a name. That is a case, and the section below is the order of operations for it.

The middle tiers are a watch list. A frozen store can come back. A registered name with nothing on it can turn into a store in an afternoon. Neither is worth a lawyer today, and both are worth a note in a calendar.

Live Shopify store

A Shopify storefront is answering on this name.

Save the evidence today. This is the tier a registrar report or a UDRP complaint is for.

Frozen Shopify store

Shopify is not serving this store right now, which is what a store shut off for non-payment looks like from outside.

Watch it. A frozen store can come back on the same name.

Resolves to something else

Something is answering on this name and it is not a Shopify storefront.

Open it yourself and see what it is. Plenty of these are parking pages and for-sale listings.

Resolves, not classified

This name points at an address. We did not get an answer about what is running there, or the scan reached its check limit before this row.

Check this one by hand. It tells you nothing on its own.

Registered, no site

This name has nameservers and nothing serving a page. Somebody holds it.

Watch it. A held name is a name that can turn into a store in an afternoon.

We could not check

The lookup did not complete for this name. That tells you nothing about it either way.

Run the scan again later for these.

No DNS answer

Nothing answered for this name. Likely unregistered. Only a registrar search confirms availability.

Nothing to do. Register the ones closest to your name if you want them off the board.

The bottom two tiers are absences and get read as absences. A lookup that did not complete tells you nothing about that name, so it is never folded into the list of names that came back empty. And a name that came back empty is likely unregistered, not proven unregistered: the only thing that proves a name is available is a registrar search.

When the lookalike is running your store

Most writing about squatted domains assumes the payload is a login page harvesting passwords. For a direct-to-consumer brand it usually is not. It is a storefront: your product photos, your descriptions, your logo, a checkout that takes real cards, and a name one keystroke off yours.

That version costs you in ways a phishing page does not. The orders are real orders your customers meant to place with you. The goods either never arrive or arrive wrong, and the complaints arrive at your inbox. The chargebacks land on the card networks under a name that reads like yours. And a clone with a working checkout can buy ads against your own brand name, so you end up paying more for traffic you already earned.

Phishing volume gives you a sense of the scale of the wider practice, with a caveat worth keeping straight. The Anti-Phishing Working Group observed 971,181 phishing attacks in the first quarter of 2026, up 13.8 percent from 853,244 in the last quarter of 2025, with 766 unique brands identified in the reports across the quarter. That is a count of attacks, not a count of lookalike domains, and the group's own definition of phishing names deceptive domain names as one of the vectors rather than the whole of it.

If a hit on your scan is running a storefront, two other things are worth checking the same afternoon. Our Shopify theme detector tells you what the clone was built with and whether it is on the same platform you are. Then see what else the store took, because a clone that took your domain shape usually took your photographs too. The playbook for the day you find one is in what to do when someone copied your website, and the wider pattern of storefronts and accounts built to pass for yours is covered in brand impersonation.

What to do about a squatted domain

Three steps, in order of cost. Start at the bottom and go up only as far as you have to.

Registrar abuse report

No fee. Every accredited registrar publishes an abuse address.

UDRP complaint

$1,500 at WIPO for one to five domains, single panelist. Around two months.

ACPA lawsuit

$1,000 to $100,000 in statutory damages per domain, at the court's discretion.

Report it to the registrar

Every ICANN-accredited registrar has to publish an abuse contact email on its homepage or another place ICANN designates, and has to take reasonable and prompt steps to investigate what gets reported to it. That obligation is in the Registrar Accreditation Agreement at section 3.18.1. It costs you an email. A registrar will not settle a trademark dispute for you, but a name serving a fake storefront with a live checkout is abuse in its own right, and that is the report that sometimes ends the whole thing in a week.

File a UDRP complaint

The Uniform Domain-Name Dispute-Resolution Policy is the arbitration route. It was drafted at WIPO and adopted by ICANN in 1999, and every generic top-level domain registrar is contractually bound by it. WIPO is one of the providers that hears the cases, not the owner of the policy.

You have to prove three things, all of them: the name is identical or confusingly similar to a mark you have rights in, the holder has no rights or legitimate interests in it, and the name was registered and is being used in bad faith. Miss one and the complaint fails.

Filing at WIPO for one to five domain names before a single panelist costs USD 1,500. A three-member panel costs USD 4,000. WIPO says a case is normally completed within around two months of receipt, and describes the procedure as faster and cheaper than going to court. It is also not exclusive: either side can still take the matter to a court.

This is a well-worn route. WIPO managed over 6,200 domain name cases in 2025, its highest caseload on record, and 6,168 cases were filed with it in 2024 under the UDRP and the country-code variations of it.

Sue under the ACPA

The statute has teeth a UDRP panel does not. A plaintiff can elect statutory damages of between $1,000 and $100,000 per domain name, at the court's discretion, any time before final judgment. That election is what makes a case against a serial registrant worth bringing, because you do not have to prove what you lost. It is also a federal lawsuit, so the cost and the calendar are of a different order than the two steps above.

Keep watching after it comes down

A name that gets transferred to you is one name. The same person can register the next permutation the following morning, which is why this is worth re-running on a schedule rather than once. The same logic applies to the trademark side of it: watching new applications that read like your mark is covered in trademark monitoring, and the full set of surfaces a brand gets copied on is in online brand protection.

This page describes how these processes work. It is not legal advice, and a real filing decision is worth an hour with a lawyer who can see your marks and your evidence.

Common questions about domain squatting

Is domain squatting illegal? +

Yes, in the United States, when it is done in bad faith. The Anticybersquatting Consumer Protection Act makes you liable if you register, traffic in or use a domain confusingly similar to a mark that was distinctive when you registered it, intending to profit from that mark. It is a civil matter, not a crime, and registering a generic name nobody holds a mark in is perfectly lawful.

Is domain squatting treason? +

No. Treason is a criminal offense against the country. Domain squatting is a civil trademark dispute, settled by a UDRP panel or a federal court. A panel can only transfer or cancel the name; money damages require a court.

When did domain squatting become illegal? +

November 29, 1999, when the Anticybersquatting Consumer Protection Act was signed into law as part of Public Law 106-113. It sits in the Lanham Act at 15 U.S.C. section 1125(d). The UDRP was adopted by ICANN the same year.

What is an example of domain squatting? +

Someone registers yourbrand-outlet.com or yuorbrand.com, points it at a storefront selling copies of your products, and runs ads against your brand name. A milder version parks the name on a for-sale page and waits for you to pay for it. Both are on the scan above.

What is the difference between domain squatting and a parked domain? +

Parking is what a name does; squatting is why it was registered. A parked name shows ads or a for-sale page instead of a site, and plenty of parked names are held by investors with no interest in anyone's brand. It becomes squatting when the name was picked because it reads like somebody else's mark and the plan is to profit from that.

Can I sue someone for registering my brand name as a domain? +

Yes, under the Anticybersquatting Consumer Protection Act, if the registrant acted in bad faith and the name is confusingly similar to a mark you have rights in. A plaintiff can elect statutory damages of $1,000 to $100,000 per domain name at the court's discretion. Most owners start with the cheaper UDRP route, which can transfer or cancel the name but never awards damages.

Sources

Every figure on this page was verified August 21, 2026.

Knockoff

Find out who's copying your products

Connect your store and see your first scan today.

Get started