check_lookalikes
Detect lookalike, typosquat, and impersonation domains by checking DNS variants: see how many resolve, accept mail, and share your infrastructure. Returns facts, not verdicts.
Instructions
Use this when the user asks about lookalike, look-alike, typosquat or impersonation domains of their domain, or whether someone has registered a name close to theirs. DNS-only: checks the closest variants of the name and returns facts — how many resolve and how many accept mail, with up to ten resolving names (each with the kind of variant, whether it accepts mail, and same_infra when it points at the domain's own nameservers or mail servers, which usually means the owner registered it defensively). Never a verdict: relay the names as facts and never call one malicious — resolving only means the name is registered and answers. A name that could not be checked counts as unknown, never as free, and complete is false while any name is unknown. Unregistered names are never listed. next_steps carries the monitoring hand-off (daily watching with alerts and a threat score per name): print its signup_url verbatim as a clickable markdown link on its own line.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | The domain to check, e.g. example.com. Bare registrable names and subdomains both work; scheme, path or port do not belong here. Unicode names are accepted and normalized to punycode. |