Solution for threat triage

Investigate whether a suspicious domain is presenting as your brand

Move from a reported indicator to connected public evidence without treating any single signal as proof.

For security, abuse, trust, and incident-response teams

Use this path to assemble context for prioritization, escalation, and human review.

An explainable threat-assessment snapshot

Connect the suspicious name to its current domain, infrastructure, trust, email, website, and declared identity signals.

Impersonation is a pattern across signals

A similar name may be benign, while a weak name match can still host deceptive content. Triage needs several kinds of evidence.

Detection supports triage, not attribution

Public evidence cannot establish intent, private ownership, legal identity, or complete campaign scope.

Workflow

Connect the suspicious name to its current domain, infrastructure, trust, email, website, and declared identity signals.

Compare the suspicious and protected identities

Use Domain Similarity and status checks to establish what the name evidence does and does not show.

Inspect infrastructure and trust

Add DNS, subdomain, IP, certificate, reputation, email-authentication, and blacklist evidence.

Collect the public presentation

Use Scrape, Technology Detection, Identity Assets, and Identity Resolution to retain relevant public website evidence.

Triage a reported login page

Start with the reported URL and protected brand domain, then connect name, domain, infrastructure, and public-page signals.

Example Request
curl -H "X-API-Key: $DOMSCAN_API_KEY" "https://domscan.net/v1/similarity?domain1=example.com&domain2=examp1e.com"
Example Response
{
  "domain1": "example.com",
  "domain2": "examp1e.com",
  "overall_similarity": 94,
  "risk_level": "high",
  "is_potential_typosquat": true
}

Products in this workflow

Connect the suspicious name to its current domain, infrastructure, trust, email, website, and declared identity signals.

Brand Monitor

Monitor domains for brand infringement and typosquatting threats.

Choose this when: Monitor domains for brand infringement and typosquatting threats.

Inputs
Domain, Company
Outcomes
Monitor, Protect, Automate
Credits
1-6
SynchronousRESTMCPSDKInteractive tool

Domain Similarity

Find domains similar to a given domain based on name patterns and keywords.

Choose this when: Find domains similar to a given domain based on name patterns and keywords.

Inputs
Domain
Outcomes
Compare, Assess, Protect
Credits
2
SynchronousRESTMCPSDK

Social Handle Availability

Check if a username is available across major social media platforms.

Choose this when: Check if a username is available across major social media platforms.

Inputs
Username
Outcomes
Verify, Discover
Credits
0-2
SynchronousBulkRESTMCPSDKInteractive tool

Domain Reputation

Check domain reputation across multiple threat intelligence sources.

Choose this when: Check domain reputation across multiple threat intelligence sources.

Inputs
Domain
Outcomes
Assess, Verify
Credits
3
SynchronousRESTMCPSDKInteractive tool

Choose this workflow when

Choose this when

You have a suspicious domain or URL and need multi-signal context for review or escalation.

Not for

Do not use it as proof of criminal intent, account ownership, legal identity, or complete campaign discovery.

Related product suites

An explainable threat-assessment snapshot

Move from a reported indicator to connected public evidence without treating any single signal as proof.