Brand Protection
Brand Protection monitors for domains registered to impersonate your brand and manages the takedown process for them. It covers look-alike detection, per-domain investigation, and takedown request tracking.
Availability: Enterprise or Threat Intelligence subscription. Lower tiers see the module with an upgrade prompt.

Enabling detection
Look-alike detection runs against the domains on your watchlist. Enable Detect look-alike domains on a domain identifier in Watchlists to begin receiving detections. Detected domains then appear in the Brand Protection views.
Look-alike views
Brand Protection presents two views in a sub-tab strip:
All Domains — every detected look-alike, with the domain it impersonates, the detected domain, takedown state, a screenshot, HTTP status, MX presence, registrar, registration date, and detection date.
Takedown Requests — the takedowns you have filed, with their status and history.
While a view loads, a column-matched skeleton table is shown.
Per-domain detail
Selecting a detected domain opens a detail view with deeper technical context, including DNS, WHOIS, SSL, HTTP response, page title, redirect chain, and related signals, to support an assessment of intent.

Takedowns
You can request a takedown for a detected domain, and you can file an ad hoc takedown for a domain you discovered yourself. Takedowns consume takedown credits; the available balance is shown on the Takedown Requests view, with a top-up path when the balance is exhausted. The Takedown Requests table summarizes each request's status, type, last update, and filing date, and can be filtered by status.
Exporting
The look-alike list can be exported to CSV with configurable scope, date range, and status.
Last updated