For the complete documentation index, see llms.txt. This page is also available as Markdown.

Brand Protection

Brand Protection monitors for domains registered to impersonate your brand and manages the takedown process for them. It covers look-alike detection, per-domain investigation, and takedown request tracking.

Availability: Enterprise or Threat Intelligence subscription. Lower tiers see the module with an upgrade prompt.

Enabling detection

Look-alike detection runs against the domains on your watchlist. Enable Detect look-alike domains on a domain identifier in Watchlists to begin receiving detections. Detected domains then appear in the Brand Protection views.

Look-alike views

Brand Protection presents two views in a sub-tab strip:

  • All Domains — every detected look-alike, with the domain it impersonates, the detected domain, takedown state, a screenshot, HTTP status, MX presence, registrar, registration date, and detection date.

  • Takedown Requests — the takedowns you have filed, with their status and history.

While a view loads, a column-matched skeleton table is shown.

Per-domain detail

Selecting a detected domain opens a detail view with deeper technical context, including DNS, WHOIS, SSL, HTTP response, page title, redirect chain, and related signals, to support an assessment of intent.

Takedowns

You can request a takedown for a detected domain, and you can file an ad hoc takedown for a domain you discovered yourself. Takedowns consume takedown credits; the available balance is shown on the Takedown Requests view, with a top-up path when the balance is exhausted. The Takedown Requests table summarizes each request's status, type, last update, and filing date, and can be filtered by status.

Exporting

The look-alike list can be exported to CSV with configurable scope, date range, and status.

Last updated