OSINT
Hunt registered lookalikes used for brand abuse
Generate lookalike domains and flag registered typosquats.
overview
What dnstwist does
dnstwist permutes a domain into typo and lookalike variants: swapped characters, omitted letters, alternate TLDs, and homoglyphs. It then checks which variants are registered.
Enrich each hit so you can rank intent. -m flags MX that could intercept email. -s fetches pages and compares fuzzy hashes to your real site. -w adds WHOIS creation dates; -g adds GeoIP.
Brand-protection slot, not asset discovery. subfinder maps your own names; dnstwist watches names that pretend to be yours. Schedule runs and escalate registered, mail-capable, or visually similar hits.
source github.com/elceef/dnstwist
use cases
Where dnstwist fits
Catch typosquatting and brand impersonation
Generate lookalike variants of your domain and filter to registered ones to find the names adversaries already hold.
Spot domains set up to intercept email
Enable the MX check to flag lookalikes with mail records, the variants most likely to be used for phishing your staff or customers.
Confirm clones of your site
Fetch pages and compare fuzzy hashes against your real site to surface lookalikes that copy your branding for credential theft.
Monitor continuously for new registrations
Schedule dnstwist and use WHOIS creation dates to catch freshly registered lookalikes as part of brand monitoring.
reference
dnstwist inputs and flags
| Name | Type | Flag | Description |
|---|---|---|---|
| domain | STRING | · | Domain name or URL to scan for lookalikes. |
| show-only-registered-domains | BOOLEAN | -r | Show only registered lookalike domains. |
| mx-check | BOOLEAN | -m | Check whether MX records could be used to intercept email. |
| compare-fuzzy-hashes | BOOLEAN | -s | Fetch pages and compare fuzzy hashes to evaluate similarity. |
| lookup-whois-db | BOOLEAN | -w | Look up WHOIS for the domain creation date. |
| geoip-lookup | BOOLEAN | -g | Resolve GeoIP location for registered variants. |
| dictionary-file | FILE | -d | Generate more variants using a dictionary. |
| dns-servers-to-query | STRING | --nameservers | DNS servers to query, comma-separated. |
Showing key inputs. dnstwist exposes 14 inputs in total.
Full flag reference (14 inputs)
| Name | Type | Flag | Description |
|---|---|---|---|
| domain | STRING | · | Domain name or URL to scan |
| mx-check | BOOLEAN | -m | Check if MX can be used to intercept emails |
| user-agent | STRING | --useragent | User-Agent STRING to send with HTTP requests |
| geoip-lookup | BOOLEAN | -g | Lookup for GeoIP location |
| override-url | STRING | --ssdeep-url | Override URL to fetch the original web page from |
| dictionary-file | FILE | -d | Generate more domains using dictionary |
| lookup-whois-db | BOOLEAN | -w | Lookup WHOIS database for creation date |
| number-of-threads | STRING | -t | Number of urls |
| compare-fuzzy-hashes | BOOLEAN | -s | Fetch web pages and compare their fuzzy hashes to evaluate similarity |
| dns-servers-to-query | STRING | --nameservers | DNS servers to query (separated with commas) |
| show-all-dns-records | BOOLEAN | -a | Show all DNS records |
| http-smtp-service-banners | BOOLEAN | -b | Determine HTTP and SMTP service banners |
| show-only-registered-domains | BOOLEAN | -r | Show only registered domain names |
| generate-domains-by-swapping-tld | FILE | --tld | Generate more domains by swapping TLD from FILE |
example
Run dnstwist
# registered lookalikes of example.com with MX and fuzzy-hash checksdnstwist -r -m -s -w -g example.comdnstwist example.com* original example.com 198.51.100.10 tld-swap example.net 198.51.100.11 MX tld-swap example.org 203.0.113.5 subdomain www.example.com 203.0.113.8 subdomain mail.example.com 198.51.100.20 subdomain api.example.com 203.0.113.15 MX tld-swap example.io 198.51.100.30* 7 registered lookalikes (sample)guidance
Choosing dnstwist
Use dnstwist to protect a brand: generate lookalikes of your domain and find which are registered, mail-capable, or visually cloned. It targets impersonation, not your own infrastructure. For mapping your real subdomains, use subfinder.
urlcrazy
Another typosquat generator. dnstwist adds fuzzy-hash page comparison and MX intercept checks.
whois-verify-targets
Confirms registration details. dnstwist generates the lookalike candidates to verify first.
subfinder
Finds your own subdomains. dnstwist finds impersonating domains others register against you.
faq
dnstwist questions
related
More OSINT tools
dnsdumpster-dns-lookup
Passive DNS records from DNSDumpster.
favup
Look up the real IP of a host from its favicon via Shodan.
Infoga
Email OSINT from public sources, with optional breach checks.
maigret
Username search that collects accounts and profile data into one dossier.
socialscan
Check whether emails and usernames are available, taken, or invalid.
dnsdumpster-host-search
Passive DNSDumpster host lookup by domain.
Run dnstwist yourself
Your domain feeds dnstwist, which generates lookalike variants, checks which are registered, and writes the impersonating domains as output.
Facts on this page come from the live Trickest tool library.