Lookalike domain scanner
Domain squatting is somebody registering a name that reads like yours in order to profit from it. Type your domain. The scan bends the name ten different ways, checks each version against up to fourteen other endings, and tells you what is standing on the ones that are taken.
Verified August 21, 2026
What comes back
- Every lookalike name that is taken, sorted by what is actually running on it.
- A flag on any live hit serving the same icon file your own site serves.
- The permutation category behind each hit, so you can see which kind of mistake it catches.
- A page you can send to a lawyer or a co-founder as-is.
Names are shown as plain text. Some of these hosts serve a fake checkout, so nothing here is clickable.
Result
Enter your domain
Every name the scan generates lands in one of seven answers.
- Live Shopify store. A Shopify storefront is answering on this name.
- Frozen Shopify store. Shopify is not serving this store right now, which is what a store shut off for non-payment looks like from outside.
- Resolves to something else. Something is answering on this name and it is not a Shopify storefront.
- Resolves, not classified. This name points at an address. We did not get an answer about what is running there, or the scan reached its check limit before this row.
- Registered, no site. This name has nameservers and nothing serving a page. Somebody holds it.
- We could not check. The lookup did not complete for this name. That tells you nothing about it either way.
- No DNS answer. Nothing answered for this name. Likely unregistered. Only a registrar search confirms availability.
The scan runs on its own page and takes a minute or two. The link stays good, so you can come back to it.
What is domain squatting?
Domain squatting, also called cybersquatting, is registering a domain name in order to profit from somebody else's brand. US law puts a definition on it. The Anticybersquatting Consumer Protection Act, signed on November 29, 1999 as part of Public Law 106-113 and sitting in the Lanham Act at 15 U.S.C. section 1125(d), makes you liable when you register, traffic in or use a domain name that is identical or confusingly similar to a mark that was distinctive at the time you registered it, and you did it with a bad-faith intent to profit from that mark.
Both halves have to be there. The name has to read like the mark, and the intent has to be bad faith. That second half is why the same parked page can be lawful on one name and unlawful on another. Registering a generic word nobody holds a mark in and selling it later is a business. Registering a misspelling of a brand and waiting for the brand to buy it is the thing the statute names.
The dispute policy every generic top-level domain is bound by says the same thing in its own words. Registering a name primarily to sell it to the mark owner or a competitor for more than your out-of-pocket costs is listed in the UDRP as evidence of bad faith. So a for-sale page on a name that spells your brand wrong is not a neutral fact. It is one of the named signals.
The board this is played on keeps getting bigger. IANA listed 1,438 endings delegated in the DNS root zone on August 20, 2026, counting the country codes and the generic ones together. Your name can be registered again on every one of them.
The ten kinds of lookalike domain, with examples
The scan above runs exactly these ten categories and no others, and seeing them side by side tells you which ones you are exposed to. Here is every category applied to one made-up brand, northpine.com.
Missing letter
Doubled letter
Swapped letters
Neighboring key
Different vowel
Hyphen added or dropped
Plural form
Lookalike characters
Word bolted on
Different ending
Ten categories, run against your name and against fourteen other endings. The table below works every one of them on a single example.
| Category | What changes | northpine.com becomes |
|---|---|---|
| Missing letter | One character dropped | nothpine.com |
| Doubled letter | One character typed twice | northppine.com |
| Swapped letters | Two neighboring characters traded | nortphine.com |
| Neighboring key | A character replaced by the key next to it | morthpine.com |
| Different vowel | One vowel replaced by another | northpune.com |
| Hyphen added or dropped | A hyphen pushed in, or an existing one removed | north-pine.com |
| Plural form | An s added or taken off the end | northpines.com |
| Lookalike characters | Characters that read as each other in most type | n0rthpine.com |
| Word bolted on | shop, store, outlet, official, sale or us, front or back | shopnorthpine.com |
| Different ending | The same name on one of up to fourteen other endings | northpine.shop |
The lookalike-character row is the one worth a second look, because it is the only category where the reader is being fooled rather than the typist. Pairs like rn and m, cl and d, and the digits 0 and 1 against the letters o and l are hard to separate in a small sans-serif font in a browser address bar.
There is a harder version of that trick this scan does not cover. Unicode contains strings that are always rendered as the same sequence of glyphs even though the characters differ, so a Cyrillic letter can stand in for a Latin one and produce a name that is visually identical rather than merely close. The Unicode Consortium's own security report uses a Cyrillic c inside citibank as the example. Those names are registered in punycode and are a different search than the one above; treat this scan as the ASCII half of the problem.
The idea of generating permutations and resolving them is not ours. dnstwist, the open-source domain name permutation engine by Marcin Ulikowski, has done it under an Apache 2.0 license for years and is where a lot of this thinking starts. What it hands back is raw DNS records, and reading those is a job. The scan above sorts the same kind of output into what a store owner has to do about each row.
Registered is not the same as dangerous
Run any brand name through a permutation scan and a pile of the results come back taken. That number on its own is close to meaningless. Common English words get registered by investors, short names get registered by everybody, and a name held by a parking service for eleven years has nothing to do with you. What matters is what is standing on the name today.
Live Shopify store
Frozen Shopify store
Resolves to something else
Resolves, not classified
Registered, no site
We could not check
No DNS answer
The last two are absences, not findings. A lookup that did not complete is not the same as a name nothing answered for, and neither one means the name is free.
The top tier is the one to act on. A lookalike name serving a live storefront, and especially one serving the same icon file your own site serves, is somebody who built a copy rather than somebody who bought a name. That is a case, and the section below is the order of operations for it.
The middle tiers are a watch list. A frozen store can come back. A registered name with nothing on it can turn into a store in an afternoon. Neither is worth a lawyer today, and both are worth a note in a calendar.
Live Shopify store
A Shopify storefront is answering on this name.
Save the evidence today. This is the tier a registrar report or a UDRP complaint is for.
Frozen Shopify store
Shopify is not serving this store right now, which is what a store shut off for non-payment looks like from outside.
Watch it. A frozen store can come back on the same name.
Resolves to something else
Something is answering on this name and it is not a Shopify storefront.
Open it yourself and see what it is. Plenty of these are parking pages and for-sale listings.
Resolves, not classified
This name points at an address. We did not get an answer about what is running there, or the scan reached its check limit before this row.
Check this one by hand. It tells you nothing on its own.
Registered, no site
This name has nameservers and nothing serving a page. Somebody holds it.
Watch it. A held name is a name that can turn into a store in an afternoon.
We could not check
The lookup did not complete for this name. That tells you nothing about it either way.
Run the scan again later for these.
No DNS answer
Nothing answered for this name. Likely unregistered. Only a registrar search confirms availability.
Nothing to do. Register the ones closest to your name if you want them off the board.
The bottom two tiers are absences and get read as absences. A lookup that did not complete tells you nothing about that name, so it is never folded into the list of names that came back empty. And a name that came back empty is likely unregistered, not proven unregistered: the only thing that proves a name is available is a registrar search.
When the lookalike is running your store
Most writing about squatted domains assumes the payload is a login page harvesting passwords. For a direct-to-consumer brand it usually is not. It is a storefront: your product photos, your descriptions, your logo, a checkout that takes real cards, and a name one keystroke off yours.
That version costs you in ways a phishing page does not. The orders are real orders your customers meant to place with you. The goods either never arrive or arrive wrong, and the complaints arrive at your inbox. The chargebacks land on the card networks under a name that reads like yours. And a clone with a working checkout can buy ads against your own brand name, so you end up paying more for traffic you already earned.
Phishing volume gives you a sense of the scale of the wider practice, with a caveat worth keeping straight. The Anti-Phishing Working Group observed 971,181 phishing attacks in the first quarter of 2026, up 13.8 percent from 853,244 in the last quarter of 2025, with 766 unique brands identified in the reports across the quarter. That is a count of attacks, not a count of lookalike domains, and the group's own definition of phishing names deceptive domain names as one of the vectors rather than the whole of it.
If a hit on your scan is running a storefront, two other things are worth checking the same afternoon. Our Shopify theme detector tells you what the clone was built with and whether it is on the same platform you are. Then see what else the store took, because a clone that took your domain shape usually took your photographs too. The playbook for the day you find one is in what to do when someone copied your website, and the wider pattern of storefronts and accounts built to pass for yours is covered in brand impersonation.
What to do about a squatted domain
Three steps, in order of cost. Start at the bottom and go up only as far as you have to.
Registrar abuse report
No fee. Every accredited registrar publishes an abuse address.
UDRP complaint
$1,500 at WIPO for one to five domains, single panelist. Around two months.
ACPA lawsuit
$1,000 to $100,000 in statutory damages per domain, at the court's discretion.
Report it to the registrar
Every ICANN-accredited registrar has to publish an abuse contact email on its homepage or another place ICANN designates, and has to take reasonable and prompt steps to investigate what gets reported to it. That obligation is in the Registrar Accreditation Agreement at section 3.18.1. It costs you an email. A registrar will not settle a trademark dispute for you, but a name serving a fake storefront with a live checkout is abuse in its own right, and that is the report that sometimes ends the whole thing in a week.
File a UDRP complaint
The Uniform Domain-Name Dispute-Resolution Policy is the arbitration route. It was drafted at WIPO and adopted by ICANN in 1999, and every generic top-level domain registrar is contractually bound by it. WIPO is one of the providers that hears the cases, not the owner of the policy.
You have to prove three things, all of them: the name is identical or confusingly similar to a mark you have rights in, the holder has no rights or legitimate interests in it, and the name was registered and is being used in bad faith. Miss one and the complaint fails.
Filing at WIPO for one to five domain names before a single panelist costs USD 1,500. A three-member panel costs USD 4,000. WIPO says a case is normally completed within around two months of receipt, and describes the procedure as faster and cheaper than going to court. It is also not exclusive: either side can still take the matter to a court.
This is a well-worn route. WIPO managed over 6,200 domain name cases in 2025, its highest caseload on record, and 6,168 cases were filed with it in 2024 under the UDRP and the country-code variations of it.
Sue under the ACPA
The statute has teeth a UDRP panel does not. A plaintiff can elect statutory damages of between $1,000 and $100,000 per domain name, at the court's discretion, any time before final judgment. That election is what makes a case against a serial registrant worth bringing, because you do not have to prove what you lost. It is also a federal lawsuit, so the cost and the calendar are of a different order than the two steps above.
Keep watching after it comes down
A name that gets transferred to you is one name. The same person can register the next permutation the following morning, which is why this is worth re-running on a schedule rather than once. The same logic applies to the trademark side of it: watching new applications that read like your mark is covered in trademark monitoring, and the full set of surfaces a brand gets copied on is in online brand protection.
This page describes how these processes work. It is not legal advice, and a real filing decision is worth an hour with a lawyer who can see your marks and your evidence.
Common questions about domain squatting
Is domain squatting illegal? +
Yes, in the United States, when it is done in bad faith. The Anticybersquatting Consumer Protection Act makes you liable if you register, traffic in or use a domain confusingly similar to a mark that was distinctive when you registered it, intending to profit from that mark. It is a civil matter, not a crime, and registering a generic name nobody holds a mark in is perfectly lawful.
Is domain squatting treason? +
No. Treason is a criminal offense against the country. Domain squatting is a civil trademark dispute, settled by a UDRP panel or a federal court. A panel can only transfer or cancel the name; money damages require a court.
When did domain squatting become illegal? +
November 29, 1999, when the Anticybersquatting Consumer Protection Act was signed into law as part of Public Law 106-113. It sits in the Lanham Act at 15 U.S.C. section 1125(d). The UDRP was adopted by ICANN the same year.
What is an example of domain squatting? +
Someone registers yourbrand-outlet.com or yuorbrand.com, points it at a storefront selling copies of your products, and runs ads against your brand name. A milder version parks the name on a for-sale page and waits for you to pay for it. Both are on the scan above.
What is the difference between domain squatting and a parked domain? +
Parking is what a name does; squatting is why it was registered. A parked name shows ads or a for-sale page instead of a site, and plenty of parked names are held by investors with no interest in anyone's brand. It becomes squatting when the name was picked because it reads like somebody else's mark and the plan is to profit from that.
Can I sue someone for registering my brand name as a domain? +
Yes, under the Anticybersquatting Consumer Protection Act, if the registrant acted in bad faith and the name is confusingly similar to a mark you have rights in. A plaintiff can elect statutory damages of $1,000 to $100,000 per domain name at the court's discretion. Most owners start with the cheaper UDRP route, which can transfer or cancel the name but never awards damages.
Sources
- The ACPA text, for the 1999 enactment and the bad-faith standard: 15 U.S.C. 1125
- The statutory damages range of $1,000 to $100,000 per domain name: 15 U.S.C. 1117
- The UDRP itself, for the three elements and the bad-faith examples: ICANN Uniform Domain-Name Dispute-Resolution Policy
- The WIPO filing fees of USD 1,500 and USD 4,000: WIPO schedule of fees
- The roughly two-month timeline and the relationship between the UDRP and the courts: WIPO guide to domain name dispute resolution and its domain name FAQ
- The 2025 caseload of over 6,200 domain name cases, and the 6,168 cases filed in 2024: WIPO caseload news, January 2026
- The count of 1,438 endings delegated in the root zone on August 20, 2026: IANA root zone TLD list
- The 971,181 phishing attacks observed in the first quarter of 2026, and the definition that names deceptive domain names: APWG Phishing Activity Trends Report, Q1 2026
- The homograph definition and the Cyrillic citibank example: Unicode Technical Report 36
- The registrar abuse contact obligation at section 3.18.1: ICANN 2013 Registrar Accreditation Agreement
- The permutation engine this idea starts from, by Marcin Ulikowski, Apache 2.0: dnstwist
Every figure on this page was verified August 21, 2026.