Type your domain. We generate every plausible lookalike — typos, unicode homoglyphs, TLD swaps, hyphen tricks — then check which ones are actually registered, which are live, and which are configured to send email as you.
A lookalike with no website looks harmless. But if it has MX records, someone configured it to receive and send mail. That's the setup behind "please update our bank details" invoice fraud — and it never touches your infrastructure, so your security tools never see it.
The Cyrillic а and the Latin a are different characters that render identically. Registered as xn-- punycode, they are indistinguishable in an email signature or a link.
A registered lookalike isn't proof of malice — resellers, fans and parking companies buy them too. We flag what's configured to be used, and mark anything resolving to your own infrastructure as probably yours. Verify before you act.
DNS lookups run in your browser over encrypted DNS-over-HTTPS (Cloudflare and Google). We never see the domain you scanned unless you press Share. Screenshots come from urlscan.io's public archive.
A typosquat domain is a registered domain deliberately made to resemble a real one, usually by a single-character change — a doubled letter, a swapped pair, an adjacent key, or a different top-level domain. The point is that a person reading quickly won't notice the difference. Typosquats are used to intercept mistyped traffic, host phishing pages, and send email that appears to come from the brand being imitated.
A homoglyph attack uses characters from other alphabets that look
identical to Latin ones. The Cyrillic "а" (U+0430) and the Latin "a"
(U+0061) are different characters that render the same way in almost every
font. Registered as an internationalised domain name, the result is encoded
as punycode beginning with xn--, so the address bar may show
what looks like the real domain while pointing somewhere else entirely.
MX records are the DNS entries that tell the internet where to deliver mail for a domain. A lookalike with MX records has been deliberately configured to send and receive email, which is the setup behind business email compromise and fake-invoice fraud. It's more significant than a live website, because the domain can be used against your customers and suppliers without ever touching your own infrastructure — so none of your security tooling sees it.
No. Domain resellers, parking companies, fans, competitors and defensive registrations by your own marketing team all produce registered lookalikes. What raises the concern is configuration: mail records, a live site, or a recent registration date. Evil Twin marks domains resolving to your own IP addresses or mail servers as probably yours, and everything it reports should be verified before you act on it.
Confirm you don't already own it, then capture evidence — the WHOIS record, the DNS records, and a screenshot of any site it serves. Warn the people most likely to be targeted, usually accounts payable and anyone handling supplier bank details. If it's actively impersonating you, you can report it to the registrar's abuse contact, and for trademark infringement the UDRP process exists. Consider registering the highest-risk unregistered variants yourself; that's usually cheaper than the alternative.
Evil Twin reads public DNS records, which is the same thing every mail server and web browser on the internet does constantly. It doesn't connect to the domains it finds, send them traffic, or probe them for vulnerabilities. Publicly available registration and DNS data is routinely used for brand protection and threat intelligence.
dnstwist is the well-established Python command-line tool that pioneered this approach, and Evil Twin's permutation logic owes a large debt to it. The difference is audience: Evil Twin runs in a browser with no install, no Python and no terminal, and presents the results as a ranked list of what to worry about rather than raw output. If you're comfortable on a command line, dnstwist is more configurable and does more.