Daily alerts for fake domains impersonating your brand

Every morning, scan for fake websites pretending to be your brand, and get a Slack alert only when one looks dangerous enough to act on.

Agentic Task
SecurityTrailsGoogle SheetsSlackOperationsMarketingNotifications & AlertsResearch & Monitoring
PromptCreate

Every morning at 7am, hunt for lookalike domains that are impersonating our brand and escalate only the ones that are actually dangerous. I want a scored shortlist, not a raw dump of every hit.

Keep our brand keyword and our real domain as inputs at the top of the run so they are easy to change. Start by using SecurityTrails Search Domains (DSL / filter) to sweep the domain dataset for hostnames containing our brand keyword, and generate variations to sweep alongside it: common misspellings, keyboard adjacent character substitutions, transposed and doubled letters, hyphenated forms, added prefixes or suffixes such as login, secure, support and pay, and the same name registered on alternate TLDs. Then run SecurityTrails Find Associated Domains on our real domain to catch registrations that share our WHOIS footprint, since those often belong to the same actor.

For every candidate, enrich before judging. Call SecurityTrails Get WHOIS for the registrar, the creation date and the registrant country. Call SecurityTrails Get Domain to see whether the name actually resolves and whether it has MX records. Call SecurityTrails Get Domain SSL Certificates to see whether anyone has issued a certificate for it.

Score each candidate rather than just listing it. Treat a domain as high risk when it was registered in the last 30 days and it resolves and it either holds a certificate or has MX records, because that combination means someone is actively preparing a working phishing page or mailbox. Treat a name that is parked, unresolved, or clearly unrelated to our brand as informational. Anything in between is medium risk: record it in the log but do not page anyone. For each high risk domain, state in one line which signals triggered the score.

Before alerting, read the log first. Use Google Sheets Get Values on the tracking sheet to load every domain already recorded, and skip alerting on any domain that already appears there so the same name is never alerted twice. Append every candidate seen on this run to the sheet with Google Sheets Append Values, one row per domain carrying the domain, the risk level, the registrar, the creation date, the registrant country, whether it resolves, whether it has MX records, whether a certificate exists, and the date first seen.

Post only the high risk finds to our security channel using Slack Send a Message. Each one should include the lookalike domain, the registrar, the registration date, the registrant country, and the one line reason it scored high, so somebody can file a phishing abuse report with the registrar immediately without opening another tool. If there are no new high risk domains, stay quiet rather than posting an empty report.

What does this prompt do?

  • Each morning it searches for web addresses that copy your brand name, including common misspellings, swapped or doubled letters, added words like login or secure, and different endings such as .net or .co
  • For every match it checks who registered it, when it was registered, which country it came from, whether the site is actually live, whether it can receive email, and whether someone has set up a security certificate for it
  • It scores each find instead of dumping a list: recently registered, live, and already set up to serve a real page or receive email is treated as high risk and worth a takedown request
  • It keeps a running spreadsheet log of every address it has ever seen so the same one is never flagged twice, and posts only the dangerous ones to Slack with the registrar and registration date you need to file an abuse report

What do I need to use this?

  • A SecurityTrails account for looking up domain and registration records
  • A Google account with a spreadsheet to use as the running log of everything seen
  • A Slack workspace and a channel where the high risk alerts should land
  • Your brand keyword and your real website address

How can I customize it?

  • Change when it runs, from every morning at 7am to twice a day or once a week
  • Adjust what counts as high risk, for example widening the recently registered window from 30 days to 90
  • Add extra misspellings, letter swaps, or web address endings that matter for your brand
  • Send high risk finds to your security channel and route the quieter informational ones to a separate channel or leave them in the spreadsheet only

FAQs

What is a lookalike domain?
It is a web address built to look almost identical to yours, using a small misspelling, a swapped letter, an extra word, or a different ending. Scammers register them to trick your customers or staff into entering passwords or paying fake invoices.
Will this flood me with alerts?
No. That is the point of the scoring step. Most copycat registrations are parked pages that never go live, and those stay in the spreadsheet log as background information. Slack only gets the ones that were registered recently, are actually live, and are already set up to serve a page or receive email.
Can it take the fake website down for me?
No, it gathers the evidence so a person can act fast. Each alert includes the registrar and the registration date, which is exactly what you need to file an abuse or phishing complaint with the company that sold the domain.
What stops me getting alerted about the same fake domain every morning?
It reads the spreadsheet log before it alerts. Anything already recorded is skipped, so each impersonating address is escalated once and then tracked quietly.
Do I need to be technical to use this?
No. You supply your brand name, your real website address, a spreadsheet, and a Slack channel. The alerts are written in plain language explaining why something looks dangerous.

Related templates

Auto-fix your calendar when a flight slips, and flag what's at risk

When your flight moves, your calendar times get corrected automatically and you get a Slack note naming the meetings you're about to miss.

Google Calendar
AviationStack
Slack
Agentic Task
Trace phishing emails to the sending IP and report abuse

Every 15 minutes, forwarded phishing reports get traced back to the server that really sent them, with a verdict in Slack and the worst senders reported.

AbuseIPDB
Gmail
Slack
Agentic Task
Weekly Amazon S3 bucket security audit posted to Slack

Every Monday, check every S3 bucket for public exposure, missing encryption and weak backup settings, then get the risks ranked in Slack.

Amazon S3
Slack Bot
Google Sheets
Agentic Task
Turn procurement portal tenders into CRM deals each morning

Every weekday at 7am, sign in to the tender portals you track, filter new notices against your bid criteria, and open a deal for the ones worth chasing.

Anchor Browser
Google Sheets
HubSpot
+1
Agentic Task
Draft polite follow-ups for emails that never got a reply

Every weekday at 4pm, spot the threads that went quiet, stage a ready-to-send nudge in your mailbox, and get a ranked Slack recap.

Aurinko
Google Sheets
Slack Bot
Agentic Task
Turn each week's football fixtures into a venue staffing plan

Every Monday, rank the week's matches by expected demand, put the big ones on your venue calendar, and post a rota-ready summary to Slack.

API-Sports
Google Calendar
Slack
Agentic Task

Find the fake versions of your brand before your customers do.

Set it up once and every morning you get a short, ranked list of the impersonating websites that are actually worth acting on.