Skip to the log
The Wire Testthe.net.im

Run 02 · Studio & Tools · field test

Look-alike scanner: 294 fakes of paypal.com, and the registry asked about the taken ones

We ran the scanner's engine on paypal.com, sent ten names through its DNS relay, asked one registry for its record, and compared dnstwist and URLCrazy.

Screenshot of the labs.llc look-alike scanner at desktop width: the headline 'Every name that could pass for yours. Then which are taken.', a domain field with paypal.com as its placeholder, a Scan button, tick boxes for homoglyphs, brand words and other endings, and sample domains to try.
EXHIBIT AThe top of the page as the local copy of build 537 served it for this log, at 1280 × 800.

Brief

What it is, and who it is for

The look-alike scanner is one of the ten instruments on the labs.llc domains desk. Give it a domain and it produces the names that could pass for it — slipped keys, doubled letters, Cyrillic or Greek letters that print like Latin ones, brand words such as login or secure, flipped bits — then checks which are delegated in DNS, asks each registered one's registry who holds it and since when, and orders the list by a published risk rule, with CSV and JSON exports.

It is for brand owners, security and IT staff, and anyone curious about near-copies of their own name.

Wiring

Where the work happens

Generation runs in the browser. window.DCLooks builds candidates with sixteen methods, turns each into the exact A-label a registry stores using the RFC 3492 encoder in whois-core.js, removes duplicates and caps the list (600 names by default). Delegation is checked through a same-origin relay (tools.php?op=ns-batch) that asks Google Public DNS for NS, A and MX, with Cloudflare as fallback; if the relay fails, the browser asks dns.google itself, six at a time. Registered names then go one by one to the labs WHOIS engine, which reads RDAP, 1.6 seconds apart.

Sources it reads

  • Google Public DNS (8.8.8.8 and dns.google over HTTPS), with Cloudflare 1.1.1.1 as fallback.
  • Registry RDAP servers, such as rdap.verisign.com for .com, through the labs WHOIS engine.
  • Unicode's confusables.txt (22 July 2025 release) for the homoglyph table; IANA's list of top-level domains.

Run table

The run, row by row

Seconds for our own probes; rival pages were logged to the minute.

Every probe in run 02, in time order, with what came back
#TimeProbeReturned
01Loaded /domains/lookalikes/ from the local copyHTTP 200. The page file is 75,178 bytes, 1,031 lines.
02Ran the page's own engine on paypal.com in JavaScriptCore (endings, brand words and IDN on; cap 600)307 raw, 294 unique, 0 dropped, 0 invalid. Biggest groups: brand words 68, other endings 49, insertion 43; one whole-script homoglyph.
03Posted ten candidates to the ns-batch relayHTTP 200 in 0.16 s: 9 registered, 1 probably unregistered. xn--pypal-4ve.com (a Cyrillic а) has an A record and no MX.
04Asked the WHOIS engine for paypa1.com, lite modeHTTP 200, 10,378 bytes with Verisign's raw RDAP: created 20 Oct 2000, nameservers at MARKMONITOR.COM.
05Read dnstwist's READMErival pageA, AAAA, NS, MX; GeoIP; fuzzy-hash and screenshot similarity; CSV and JSON; a browser version at dnstwist.it.
06Read URLCrazy's READMErival page17 typo types, four keyboard layouts, 8,000+ misspellings; popularity estimate; IP country.

Findings

The lengths it goes to

  1. Homoglyphs are checked pair by pair against Unicode's own confusables file, and every candidate becomes the A-label a registry really stores — so the scanner tests xn--pypal-4ve.com, not a string that merely looks right on screen.evidence · dc-looks.js 56–68, 167–200; run row 02
  2. The order is a printed rule: method weight, +25 for mail, +10 for a web address, +30 if registered in the last ninety days, −30 if held at the original's brand-protection registrar, −15 if run by its DNS provider. paypa1.com — MarkMonitor, since 2000 — is the defensive pattern it marks down.evidence · dc-looks.js 660–724, 672–675; run row 04
  3. The wording will not overclaim: no delegation means 'probably unregistered', never 'available'; a failed check is Unknown; no look-alike is ever made into a link.evidence · dc-looks.js 20–27; tools_dns.php 9–12
  4. When candidates exceed the cap it takes one from each method in turn, so hundreds of typing slips cannot crowd out rarer methods such as homoglyphs.evidence · dc-looks.js 571–597
  5. If its relay goes down it asks dns.google directly and says so above the table.evidence · dc-looks.js 958–995

Against the field

Set beside 2 rivals

Rival 01read

dnstwist

An open-source permutation engine for finding typosquats and impersonation domains, with a browser version.

Where it is ahead

  • It compares what a look-alike serves with the original — fuzzy hashes of the HTML, perceptual hashes of screenshots — which is how live phishing surfaces.
  • AAAA, GeoIP and rogue-MX checks; scriptable and schedulable.

Where Look-alike scanner goes further

  • Registrar and creation date from each registry, feeding a published ordering.
  • Runs in a web page with a sentence explaining every method, and never links the fakes.
Rival 02read

URLCrazy

An OSINT command-line tool that generates and tests domain typos and variations.

Where it is ahead

  • Four keyboard layouts and a list of more than 8,000 common misspellings and homophones.
  • A popularity estimate for each typo and the country of its IP.

Where Look-alike scanner goes further

  • Registry facts rather than DNS alone, with an ordering built on them.
  • States DNS's limits in its verdicts — we saw 'probably-unregistered' in the relay's reply.

Faults

Where it falls short

  1. It never looks at what a registered look-alike is serving: no screenshots, no HTML or perceptual similarity, no GeoIP — all of which dnstwist does.
  2. Keyboard slips assume QWERTY only (dc-looks.js 49–56); URLCrazy also covers AZERTY, QWERTZ and DVORAK.
  3. Slow on big lists: 1.6 seconds per registry lookup, so hundreds of registered names take minutes; a default cap of 600.
  4. A one-off scan. There is no schedule, no watch list and no alert when a new look-alike appears.

Sign-off

Log closed at

Held up
Generation, the DNS relay and RDAP all answered, and the wording never outran the evidence.
Fell short
Blind to what the fakes serve; QWERTY only; no monitoring.
Reach for it when
You want to know who holds the near-copies of a domain and since when, with nothing to install.
Look elsewhere when
You need to know whether a fake is serving a phishing page, or want a scan you can script and schedule yourself — dnstwist.