Domain protection
Find lookalike domains. Review the evidence.
NameSignal checks configured public certificate logs for names that resemble your brand. Review a match, collect public evidence, and prepare a response without opening the suspected site.
What it catches
Typosquats
One keystroke away — acmetimeshets.com, acmetimesheet.com.
Lookalike characters
Cyrillic and Greek letters that render identically to Latin ones.
Combined words
Your name glued to a lure — acme-timesheets-login, secure-acme.
Domain swaps
Your exact name on a different ending, including high-abuse TLDs.
Deceptive subdomains
Your real domain used as a subdomain of somebody else’s.
Your own domains go on an allowlist during setup, so your certificate renewals are never reported back to you as impersonations. That one step is the difference between alerts you read and alerts you learn to ignore.
A domain is never one click away
This is a product about phishing. Every suspected domain is defanged and rendered as plain text — in the app and in email — so reviewing an alert can never take you to the site it is about.
combosquat · score 92/100
Investigation, without you visiting the site
NameSignal reads public registration (RDAP) and DNS records, and its isolated scanner reads the suspect page as plain text: no script runs, no image loads, nothing is submitted. You never have to open it.
- Registrar
- Example Registrar LLC
- Abuse contact
- abuse@example-registrar.test
- Nameservers
- ns1.example-host.test, ns2.example-host.test
- First seen
- 4 March 2026, 09:12 UTC
Illustrative values — real evidence comes from the registrar.
A report you can share
Download a dated, printable HTML report from any alert you can access. It includes the match, public evidence, case status and a next step. Private case notes and draft correspondence stay out of the client report.
Open the downloaded report and print it to PDF if needed. Reports use defanged domains, contain no scripts or remote resources, and state the limits of the evidence. Sharing the file is your choice.
Open sample report · fictional dataA takedown notice, already written
Investigating an alert also drafts the abuse report, populated with the evidence collected. This is the real generator output, not a sample of what it might look like.
Generated from a fictional alert
Subject: Abuse report — suspected impersonation domain acme-timesheets-login.com To the Abuse / Trust & Safety team, I am reporting the domain acme-timesheets-login.com, which appears to imitate the Acme Timesheets brand and may create a risk of customer confusion or phishing. Evidence: - Reported domain: acme-timesheets-login.com - Brand being imitated: Acme Timesheets - First observed in Certificate Transparency data: 2026-03-04T09:12:00.000Z - Detection type: combosquat - Risk score: 92/100 - Detection reason: “acmetimesheets” paired with phishing lure “login” Please investigate this registration and any associated hosting under your acceptable-use and abuse policies. If you require proof of trademark rights, customer reports, screenshots, or identity verification, please reply with the exact materials needed. This notice is a request for investigation and does not claim that the registrant has been found legally liable. Regards, Authorized representative for Acme Timesheets
Press “Take it down” on the alert and confirm you act for the brand, and we review the evidence, file the report with the company the domain was registered with and track it until it is gone. Or send the draft yourself. Either way it is filed only when you ask, and NameSignal does not give legal advice: a takedown is a claim about your rights, made in your name.
What the free plan includes
Free
3 domains
Pro
Every domain
Agency
Every domain
The free plan includes 3 suspicious domains, and they stay the same rather than rotating — so you can investigate them properly and follow a takedown through. If we find more, we tell you how many. Upgrading unlocks all of them at once.
What it cannot see
- Certificate Transparency records certificates, not every domain registration. Domains without a publicly logged certificate may not appear. Separate DNS sweeps check a bounded set of common lookalike names.
- NameSignal polls a configured set of public certificate logs across operators. Coverage is not exhaustive, and upstream outages or recovery work can delay or leave gaps in findings. Check the current coverage status.
- A certificate match cannot tell you whether a website is malicious, whether an email has been sent, or whether the domain will be used for impersonation.
See also: help & FAQ
Start with one brand, free.
No card required. Setup takes a couple of minutes, and monitoring starts within about a minute of adding your brand.
Monitor my brand