Evil Twin

Someone else owns
a domain that looks like yours.

Type your domain. We generate every plausible lookalike — typos, unicode homoglyphs, TLD swaps, hyphen tricks — then check which ones are actually registered, which are live, and which are configured to send email as you.

Try
Scan options
Preparing…
0 / 0 checked · 0 registered

Why MX records are the scary part

A lookalike with no website looks harmless. But if it has MX records, someone configured it to receive and send mail. That's the setup behind "please update our bank details" invoice fraud — and it never touches your infrastructure, so your security tools never see it.

Unicode domains are invisible

The Cyrillic а and the Latin a are different characters that render identically. Registered as xn-- punycode, they are indistinguishable in an email signature or a link.

What this doesn't prove

A registered lookalike isn't proof of malice — resellers, fans and parking companies buy them too. We flag what's configured to be used, and mark anything resolving to your own infrastructure as probably yours. Verify before you act.

Where the data comes from

DNS lookups run in your browser over encrypted DNS-over-HTTPS (Cloudflare and Google). We never see the domain you scanned unless you press Share. Screenshots come from urlscan.io's public archive.