Daily alerts for fake domains impersonating your brand

By General Input

Every morning, scan for fake websites pretending to be your brand, and get a Slack alert only when one looks dangerous enough to act on.

Integrations

  • SecurityTrails
  • Google Sheets
  • Slack

Type

Agentic Task

Categories

  • Operations
  • Marketing

Every morning at 7am, hunt for lookalike domains that are impersonating our brand and escalate only the ones that are actually dangerous. I want a scored shortlist, not a raw dump of every hit.

Keep our brand keyword and our real domain as inputs at the top of the run so they are easy to change. Start by using SecurityTrails Search Domains (DSL / filter) to sweep the domain dataset for hostnames containing our brand keyword, and generate variations to sweep alongside it: common misspellings, keyboard adjacent character substitutions, transposed and doubled letters, hyphenated forms, added prefixes or suffixes such as login, secure, support and pay, and the same name registered on alternate TLDs. Then run SecurityTrails Find Associated Domains on our real domain to catch registrations that share our WHOIS footprint, since those often belong to the same actor.

For every candidate, enrich before judging. Call SecurityTrails Get WHOIS for the registrar, the creation date and the registrant country. Call SecurityTrails Get Domain to see whether the name actually resolves and whether it has MX records. Call SecurityTrails Get Domain SSL Certificates to see whether anyone has issued a certificate for it.

Score each candidate rather than just listing it. Treat a domain as high risk when it was registered in the last 30 days and it resolves and it either holds a certificate or has MX records, because that combination means someone is actively preparing a working phishing page or mailbox. Treat a name that is parked, unresolved, or clearly unrelated to our brand as informational. Anything in between is medium risk: record it in the log but do not page anyone. For each high risk domain, state in one line which signals triggered the score.

Before alerting, read the log first. Use Google Sheets Get Values on the tracking sheet to load every domain already recorded, and skip alerting on any domain that already appears there so the same name is never alerted twice. Append every candidate seen on this run to the sheet with Google Sheets Append Values, one row per domain carrying the domain, the risk level, the registrar, the creation date, the registrant country, whether it resolves, whether it has MX records, whether a certificate exists, and the date first seen.

Post only the high risk finds to our security channel using Slack Send a Message. Each one should include the lookalike domain, the registrar, the registration date, the registrant country, and the one line reason it scored high, so somebody can file a phishing abuse report with the registrar immediately without opening another tool. If there are no new high risk domains, stay quiet rather than posting an empty report.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentLocal listing health board for every location you manageWin back LiveChat visitors whose chats went unansweredLet support send one-off Loops emails without an engineerStop cold emails to anyone with a live deal in PipedriveiMessage campaign console with pre-flight checks and delivery boardChat quality review board for LiveChat support leadsLinkedIn Ads budget pacing dashboard for every client accountFront desk appointment confirmation board for the next 3 daysGive your team Looker numbers without buying more seats