Catch fake websites impersonating your brand every morning

By General Input

Every morning at 7am, spot new copycat and phishing sites using your name, ranked by how convincing they are, before your customers find them.

Integrations

  • urlscan.io
  • Google Sheets
  • Slack

Type

Agentic Task

Categories

  • Marketing
  • Operations

Every morning at 7am, hunt for websites that are impersonating our brand and post anything genuinely new to our brand protection Slack channel. Before running this, fill in our real details wherever it says BRAND_NAME (our brand name as it appears inside domain names, for example "ourbrand"), OUR_DOMAINS (our official domains, for example ourbrand.com and ourbrand.org), OUR_CDN (the domain our assets are served from), and PARTNER_DOMAINS (known partner and vendor sites we never want flagged).

Start with urlscan Search Scans. Run it more than once, because each query shape catches a different kind of impostor and no single search finds them all.

Search one, lookalike hostnames. Use a regex on the page domain that matches our brand name while excluding our real domains: page.domain:(/.*BRAND_NAME.*/ AND NOT ourbrand.com AND NOT ourbrand.org). This catches typo variants, hyphenated versions, extra words like login or support, and the same name on a different top level domain.

Search two, hotlinked assets. Shape it as domain:ourbrand.com AND NOT page.domain:ourbrand.com. This finds pages served from someone else's hostname that are still requesting logos, stylesheets, or scripts from our real infrastructure. It is a strong signal that someone copied our site wholesale rather than rebuilding it, and it catches impersonators whose domain name looks nothing like ours.

Search three, already flagged pages. Combine the lookalike pattern with task.tags:phishing and verdicts.overall.malicious:true to surface hits that other researchers or urlscan itself have already judged to be malicious. Treat these as high priority since someone else has already confirmed the intent.

Notes on searching. urlscan search accepts full Lucene syntax. Results come back newest first and a single call returns at most the requested size, defaulting to 100. If there are more results than that, page by taking the sort array from the last result object and passing it as the search_after parameter on the next call. Since this runs daily, restrict to recent scans rather than pulling the whole history, and rely on the review log below as the real guard against repeats. One caveat: the brand field on search results is a urlscan Pro feature, so do not build the logic around it. Lean on the domain and hotlink queries plus the verdicts, which all work on the free tier, and treat brand attribution as a bonus when it happens to be present.

Before alerting on anything, deduplicate. Use Google Sheets Get Values to read our running log of domains we have already reviewed, then drop every candidate whose domain already appears in that log. Separately, drop anything on our permanent allowlist: OUR_DOMAINS, OUR_CDN, and PARTNER_DOMAINS. Those must never generate an alert. What survives both filters is the list of genuinely new candidates.

For each new candidate, gather evidence. Use urlscan Get Scan Result to pull the IP address, the hosting provider, the country, and the overall verdict. Use urlscan Get Screenshot to retrieve the stored image of the page so a human can eyeball it without ever visiting the live site. Include the screenshot and a link to the full scan result alongside each finding.

Then judge how convincing each impersonation actually is, and rank them. Weigh how closely the screenshot resembles our real site, how plausible the hostname reads as one of ours, whether the page is hotlinking our logos or stylesheets, whether it is capturing logins or payment details, whether the hosting looks unrelated to our own, and whether there is already a phishing tag or malicious verdict on it. A pixel accurate clone with a live login form matters far more than a parked page with our name in it, and the ranking should reflect that.

Post the new finds to our brand protection Slack channel with Slack Send a Message, leading with the most convincing ones. For each candidate give the domain, one or two plain sentences on why it looks like a copy of us, the IP address and hosting provider, the verdict, and links to the scan result and screenshot. Keep it skimmable so someone can triage the whole thing over coffee.

If nothing survives the filtering, still post a short message saying the run completed and found no new impersonating domains today. Say it plainly. Silence should always mean something is broken, never that everything is fine.

Finally, use Google Sheets Append Values to append every new domain from this run to the review log, along with the date it was first seen and a one line note on how convincing it looked. This is what keeps tomorrow's run quiet, so do it whether or not we decide to act on a given domain.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentLocal listing health board for every location you manageWin back LiveChat visitors whose chats went unansweredLet support send one-off Loops emails without an engineerStop cold emails to anyone with a live deal in PipedriveiMessage campaign console with pre-flight checks and delivery boardChat quality review board for LiveChat support leadsLinkedIn Ads budget pacing dashboard for every client accountFront desk appointment confirmation board for the next 3 daysGive your team Looker numbers without buying more seats