Monitoring & Risk

Lookalike Monitoring: find domains impersonating yours

DMARC stops people sending from your exact domain. It does nothing about examp1e.com or example-invoices.com. Lookalike Monitoring finds those, tells you which ones are dangerous, and lets you ask for them to be taken down.

Where to find it
Monitoring & Risk → Lookalike Monitoring

What you'll see

Every domain you own is scanned automatically. For each, a count of lookalikes found and a risk level (Low, Medium or High, scaled by how many there are). Expand a domain to see the individual lookalike domains, each tagged with the trick used to make it: a swapped letter, a look-alike character, a missing dot, an extra word.

What to do about one

  • Analyze runs a live check: is the domain actually online, does it have its own mail setup, is it built enough to be a real risk or just parked?
  • Takedown sends a request to the DMARCS team, who review it and pursue removal with the registrar or host.
Not every lookalike is malicious. Many are parked by domain speculators and never used. Analyze first; save takedown requests for domains with a website, mail records, or a recent registration date.

You may see this page titled Risk Explorer in some parts of the app; it's the same tool.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support