Run 02 · Studio & Tools · field test
Look-alike scanner: 294 fakes of paypal.com, and the registry asked about the taken ones
We ran the scanner's engine on paypal.com, sent ten names through its DNS relay, asked one registry for its record, and compared dnstwist and URLCrazy.
Brief
What it is, and who it is for
The look-alike scanner is one of the ten instruments on the labs.llc domains desk. Give it a domain and it produces the names that could pass for it — slipped keys, doubled letters, Cyrillic or Greek letters that print like Latin ones, brand words such as login or secure, flipped bits — then checks which are delegated in DNS, asks each registered one's registry who holds it and since when, and orders the list by a published risk rule, with CSV and JSON exports.
It is for brand owners, security and IT staff, and anyone curious about near-copies of their own name.
Wiring
Where the work happens
Generation runs in the browser. window.DCLooks builds candidates with sixteen methods, turns each into the exact A-label a registry stores using the RFC 3492 encoder in whois-core.js, removes duplicates and caps the list (600 names by default). Delegation is checked through a same-origin relay (tools.php?op=ns-batch) that asks Google Public DNS for NS, A and MX, with Cloudflare as fallback; if the relay fails, the browser asks dns.google itself, six at a time. Registered names then go one by one to the labs WHOIS engine, which reads RDAP, 1.6 seconds apart.
Sources it reads
- Google Public DNS (8.8.8.8 and dns.google over HTTPS), with Cloudflare 1.1.1.1 as fallback.
- Registry RDAP servers, such as rdap.verisign.com for .com, through the labs WHOIS engine.
- Unicode's confusables.txt (22 July 2025 release) for the homoglyph table; IANA's list of top-level domains.
Run table
The run, row by row
| # | Time | Probe | Returned |
|---|---|---|---|
| 01 | Loaded /domains/lookalikes/ from the local copy | HTTP 200. The page file is 75,178 bytes, 1,031 lines. | |
| 02 | Ran the page's own engine on paypal.com in JavaScriptCore (endings, brand words and IDN on; cap 600) | 307 raw, 294 unique, 0 dropped, 0 invalid. Biggest groups: brand words 68, other endings 49, insertion 43; one whole-script homoglyph. | |
| 03 | Posted ten candidates to the ns-batch relay | HTTP 200 in 0.16 s: 9 registered, 1 probably unregistered. xn--pypal-4ve.com (a Cyrillic а) has an A record and no MX. | |
| 04 | Asked the WHOIS engine for paypa1.com, lite mode | HTTP 200, 10,378 bytes with Verisign's raw RDAP: created 20 Oct 2000, nameservers at MARKMONITOR.COM. | |
| 05 | Read dnstwist's READMErival page | A, AAAA, NS, MX; GeoIP; fuzzy-hash and screenshot similarity; CSV and JSON; a browser version at dnstwist.it. | |
| 06 | Read URLCrazy's READMErival page | 17 typo types, four keyboard layouts, 8,000+ misspellings; popularity estimate; IP country. |
Findings
The lengths it goes to
- Homoglyphs are checked pair by pair against Unicode's own confusables file, and every candidate becomes the A-label a registry really stores — so the scanner tests
xn--pypal-4ve.com, not a string that merely looks right on screen.evidence · dc-looks.js 56–68, 167–200; run row 02 - The order is a printed rule: method weight, +25 for mail, +10 for a web address, +30 if registered in the last ninety days, −30 if held at the original's brand-protection registrar, −15 if run by its DNS provider. paypa1.com — MarkMonitor, since 2000 — is the defensive pattern it marks down.evidence · dc-looks.js 660–724, 672–675; run row 04
- The wording will not overclaim: no delegation means 'probably unregistered', never 'available'; a failed check is Unknown; no look-alike is ever made into a link.evidence · dc-looks.js 20–27; tools_dns.php 9–12
- When candidates exceed the cap it takes one from each method in turn, so hundreds of typing slips cannot crowd out rarer methods such as homoglyphs.evidence · dc-looks.js 571–597
- If its relay goes down it asks dns.google directly and says so above the table.evidence · dc-looks.js 958–995
Against the field
Set beside 2 rivals
dnstwist
An open-source permutation engine for finding typosquats and impersonation domains, with a browser version.
Where it is ahead
- It compares what a look-alike serves with the original — fuzzy hashes of the HTML, perceptual hashes of screenshots — which is how live phishing surfaces.
- AAAA, GeoIP and rogue-MX checks; scriptable and schedulable.
Where Look-alike scanner goes further
- Registrar and creation date from each registry, feeding a published ordering.
- Runs in a web page with a sentence explaining every method, and never links the fakes.
URLCrazy
An OSINT command-line tool that generates and tests domain typos and variations.
Where it is ahead
- Four keyboard layouts and a list of more than 8,000 common misspellings and homophones.
- A popularity estimate for each typo and the country of its IP.
Where Look-alike scanner goes further
- Registry facts rather than DNS alone, with an ordering built on them.
- States DNS's limits in its verdicts — we saw 'probably-unregistered' in the relay's reply.
Faults
Where it falls short
- It never looks at what a registered look-alike is serving: no screenshots, no HTML or perceptual similarity, no GeoIP — all of which dnstwist does.
- Keyboard slips assume QWERTY only (dc-looks.js 49–56); URLCrazy also covers AZERTY, QWERTZ and DVORAK.
- Slow on big lists: 1.6 seconds per registry lookup, so hundreds of registered names take minutes; a default cap of 600.
- A one-off scan. There is no schedule, no watch list and no alert when a new look-alike appears.
Sign-off
Log closed at
- Held up
- Generation, the DNS relay and RDAP all answered, and the wording never outran the evidence.
- Fell short
- Blind to what the fakes serve; QWERTY only; no monitoring.
- Reach for it when
- You want to know who holds the near-copies of a domain and since when, with nothing to install.
- Look elsewhere when
- You need to know whether a fake is serving a phishing page, or want a scan you can script and schedule yourself — dnstwist.