Lookalike domain monitoring
Catch the domain that's pretending to be you.
Phishing campaigns and invoice fraud start the same way: someone registers a domain one glyph away from yours. Bastion generates the plausible variants of your domain, watches public DNS and certificate transparency for them, and alerts you when one is registered or goes live — while it's still parked, before it's in anyone's inbox.
No card required to start. Plans from $25/month; first scan in about a minute.
Why lookalikes work
One glyph is enough
examp1e.com, exarnple.com, example-billing.com — under time pressure, in an email client's font, they all read as you. That's the entire trick, and it keeps working.
The target is your counterparties
Lookalikes are used against your customers and suppliers more than against you: a spoofed invoice with changed bank details, sent from a domain that passes a glance.
Registration is the tell
A campaign needs the domain first, then usually a certificate. Both events are visible in public data days or weeks before the first email lands — if anyone is watching.
Nobody owns the watching
Checking registrations by hand is nobody's job, so it happens never. The first signal most companies get is a confused customer forwarding the phish.
How Bastion watches
Variants generated, then monitored
Typosquats, homoglyphs and common look-alike patterns of your verified domains, checked continuously against public DNS and CT logs. Passive only — no interaction with the suspect domain's owners.
Alerted at registration, not at impact
A newly registered lookalike, a certificate issued for one, or one starting to serve content each raise a change alert — the earliest points at which you can act.
Evidence ready for a takedown
The finding carries the observed records — registration, DNS, certificate — which is the packet a registrar abuse desk or your legal team needs to start a complaint.
Part of the same feed
Lookalike events land in the same change feed and alert channels as everything else — one place to watch, not another portal.
Common questions
Can Bastion take a phishing domain down?
No — takedowns go through the registrar or hosting provider's abuse process. Bastion's job is to hand you the early warning and the evidence so that process starts on day one instead of after the campaign.
Will I be flooded with alerts for parked domains?
No. Most variant registrations are unremarkable, and passive watching distinguishes states: registration, certificate issuance, live content. You hear when something changes state — and like every Bastion finding, ones you've assessed can be accepted or muted.
Is monitoring someone else's domain legal?
The watching is passive reads of public data — DNS queries and certificate transparency logs, the same lookups any mail server performs. Bastion never probes or interacts with the lookalike's infrastructure.
Know the day the lookalike appears.
Verify your domain and the variant watch starts with your first scan.
Start your 7-day trialNo card required to start. Cancel any time.