How we check
Everything here is public. Verify any of it yourself.
This page exists so you don't have to take our word for anything. If you're the kind of person who checks, good. So are we.
What we look at
- Your DMARC record. A public DNS entry that tells Gmail, Outlook and others what to do when someone sends email pretending to be you: nothing, send to spam, or refuse.
- Your SPF record. The public list of servers allowed to send your mail. We follow every "include" and count the lookups, because more than ten breaks the check silently.
- Your DKIM signatures. We ask for the common signature names (default, google, selector1, k1 and others). We can only see the ones we know to ask for, so "none found" means "none of the usual ones," not "definitely none."
- Your mail servers. Public MX records, which also tell us who handles your mail.
- Look-alike addresses. We generate variations of your name (a missing letter, two letters swapped, 1 for l, rn for m, added words like "closing" or "billing", other endings like .co and .net) and ask public name servers whether each one exists.
- Registration records. For the ones that exist, we read the public registry record for the creation date and the registrar.
Where the data comes from
- Public DNS, through Cloudflare's and Google's public resolvers.
- RDAP, the official registry lookup service that replaced WHOIS, reached through the registry for each ending (.com and .net through Verisign, and so on) using IANA's public directory.
- Certificate transparency logs (crt.sh), the public record of security certificates issued for a name. Used in the written plan.
- For live copycat sites in the written plan, one ordinary page request, the same as a browser visiting. We never submit a form, never log in, and never interact with anything.
What we never do
- We never log in to anything of yours, and never ask for a password.
- We never change your DNS. The one exception is a Managed Rollout, which happens only after you sign an agreement saying exactly what we'll change, and it's staged over 60 to 90 days.
- We never send email as you, or to your customers.
- We never sell or share what we find. Any research we publish counts domains, never names them.
What we store
Each check saves the domain, the public records we read, the time, and your browser's user agent (so we know whether to design for phones). We don't store your IP address with the result. If you ask for the result by email, we store that email so we can send it and follow up once.
A shared result link lives for 30 days, carries no domain name in the address, and isn't indexed by search engines.
What we can't tell you
- Who owns a copycat domain. Owner details are hidden on most domains. We can show when it was registered, through which company, whether it can send email and where it's hosted. Only registrars, courts and law enforcement can get the name.
- Whether your email has already been forged. The check shows whether it's possible. Finding out whether it's happening takes DMARC reports, which start arriving a day or two after you publish the record we give you.
- Whether a copycat is dangerous. Plenty of look-alike domains belong to unrelated businesses or investors. We tell you what the record says and let the facts speak.
How we talk about what we find
We never say "protected," because no setting makes impersonation impossible. We mark an address as "needs attention," never as a person to accuse, because we don't know who registered it or why. Everything we print about an address is something it has, not something its owner is. When we notify a business that a look-alike of their name appeared, the notice contains the evidence and no sales pitch.
Questions
Write to us and a person answers, usually the same day: hello@copycatcheck.com. ATXworks.dev.