Evil Twin
Free · nothing stored · runs in your browser

Someone else owns
a domain that looks like yours.

Type your domain. We generate every plausible lookalike — typos, unicode homoglyphs, TLD swaps, hyphen tricks — then check which ones are actually registered, which are live, and which are configured to send email as you.

Try
Scan options
Preparing…
0 / 0 checked · 0 registered

Scan results

How Evil Twin works

Why MX records are the scary part

A lookalike with no website looks harmless. But if it has MX records, someone configured it to receive and send mail. That's the setup behind "please update our bank details" invoice fraud — and it never touches your infrastructure, so your security tools never see it.

Unicode domains are invisible

The Cyrillic а and the Latin a are different characters that render identically. Registered as xn-- punycode, they are indistinguishable in an email signature or a link.

What this doesn't prove

A registered lookalike isn't proof of malice — resellers, fans and parking companies buy them too. We flag what's configured to be used, and mark anything resolving to your own infrastructure as probably yours. Verify before you act.

Where the data comes from

DNS lookups run in your browser over encrypted DNS-over-HTTPS (Cloudflare and Google). We never see the domain you scanned unless you press Share. Screenshots come from urlscan.io's public archive.

Questions people ask

What is a typosquat domain?

A typosquat domain is a registered domain deliberately made to resemble a real one, usually by a single-character change — a doubled letter, a swapped pair, an adjacent key, or a different top-level domain. The point is that a person reading quickly won't notice the difference. Typosquats are used to intercept mistyped traffic, host phishing pages, and send email that appears to come from the brand being imitated.

What is a homoglyph or IDN homograph attack?

A homoglyph attack uses characters from other alphabets that look identical to Latin ones. The Cyrillic "а" (U+0430) and the Latin "a" (U+0061) are different characters that render the same way in almost every font. Registered as an internationalised domain name, the result is encoded as punycode beginning with xn--, so the address bar may show what looks like the real domain while pointing somewhere else entirely.

Why do MX records on a lookalike domain matter?

MX records are the DNS entries that tell the internet where to deliver mail for a domain. A lookalike with MX records has been deliberately configured to send and receive email, which is the setup behind business email compromise and fake-invoice fraud. It's more significant than a live website, because the domain can be used against your customers and suppliers without ever touching your own infrastructure — so none of your security tooling sees it.

Does a registered lookalike domain mean I'm being attacked?

No. Domain resellers, parking companies, fans, competitors and defensive registrations by your own marketing team all produce registered lookalikes. What raises the concern is configuration: mail records, a live site, or a recent registration date. Evil Twin marks domains resolving to your own IP addresses or mail servers as probably yours, and everything it reports should be verified before you act on it.

What should I do if I find a lookalike domain with MX records?

Confirm you don't already own it, then capture evidence — the WHOIS record, the DNS records, and a screenshot of any site it serves. Warn the people most likely to be targeted, usually accounts payable and anyone handling supplier bank details. If it's actively impersonating you, you can report it to the registrar's abuse contact, and for trademark infringement the UDRP process exists. Consider registering the highest-risk unregistered variants yourself; that's usually cheaper than the alternative.

Is it legal to scan for lookalike domains?

Evil Twin reads public DNS records, which is the same thing every mail server and web browser on the internet does constantly. It doesn't connect to the domains it finds, send them traffic, or probe them for vulnerabilities. Publicly available registration and DNS data is routinely used for brand protection and threat intelligence.

How is Evil Twin different from dnstwist?

dnstwist is the well-established Python command-line tool that pioneered this approach, and Evil Twin's permutation logic owes a large debt to it. The difference is audience: Evil Twin runs in a browser with no install, no Python and no terminal, and presents the results as a ranked list of what to worry about rather than raw output. If you're comfortable on a command line, dnstwist is more configurable and does more.