Domain and Brand Monitoring
Watching for impersonation, typosquatting, and unauthorized brand use via search.
The problem
Brand impersonation — typosquatted domains, fake social profiles, counterfeit product listings — tends to surface in search results well before a brand's own monitoring team stumbles across it manually, but the volume of lookalike domains and profiles registered against any recognizable brand makes manual scanning impractical.
How the workflow is built
Recurring queries combine the brand name with common typosquat patterns and impersonation-indicative terms (login, verify, support, official), alongside `site:`-scoped searches on major social and marketplace platforms for unauthorized use of brand assets, with hits routed to a takedown or legal review workflow.
Example queries
"[brand]" login verify account -site:[official domain]"[brand name]" official store site:instagram.comcounterfeit "[brand]" for sale marketplace
Pitfalls to watch for
- Search engines actively deindex the most egregious phishing domains reasonably quickly, which means a search-only monitoring approach systematically undercounts the most dangerous impersonation attempts precisely because they're often already flagged and removed from results by the time a query catches them — WHOIS and domain-registration monitoring should run alongside, not instead of, search.
- Legitimate fan pages, resellers, and parody accounts can trigger the same detection patterns as genuine impersonation, so a workflow needs a review step before any takedown action, not automatic action on every hit.
- Brand names that are also common words or overlap with unrelated companies produce a high false-positive rate, making precise query construction and result filtering more important here than raw query volume.