> For the complete documentation index, see [llms.txt](https://knowledge.whiteintel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://knowledge.whiteintel.io/protection-modules/brand-protection.md).

# Brand Protection

Brand Protection monitors for domains registered to impersonate your brand and manages the takedown process for them. It covers look-alike detection, per-domain investigation, and takedown request tracking.

**Availability:** Enterprise or Threat Intelligence subscription. Lower tiers see the module with an upgrade prompt.

<figure><img src="/files/zHa1crE9OdWmbY0dGOFr" alt=""><figcaption></figcaption></figure>

### Enabling detection

Look-alike detection runs against the domains on your watchlist. Enable **Detect look-alike domains** on a domain identifier in Watchlists to begin receiving detections. Detected domains then appear in the Brand Protection views.

### Look-alike views

Brand Protection presents two views in a sub-tab strip:

* **All Domains** — every detected look-alike, with the domain it impersonates, the detected domain, takedown state, a screenshot, HTTP status, MX presence, registrar, registration date, and detection date.
* **Takedown Requests** — the takedowns you have filed, with their status and history.

While a view loads, a column-matched skeleton table is shown.

### Per-domain detail

Selecting a detected domain opens a detail view with deeper technical context, including DNS, WHOIS, SSL, HTTP response, page title, redirect chain, and related signals, to support an assessment of intent.

<figure><img src="/files/jHEmXGSWgeP4qjCKIHPk" alt=""><figcaption></figcaption></figure>

### Takedowns

You can request a takedown for a detected domain, and you can file an ad hoc takedown for a domain you discovered yourself. Takedowns consume takedown credits; the available balance is shown on the Takedown Requests view, with a top-up path when the balance is exhausted. The Takedown Requests table summarizes each request's status, type, last update, and filing date, and can be filtered by status.

### Exporting

The look-alike list can be exported to CSV with configurable scope, date range, and status.
