Execute a lookalike search

Learn how to execute Lookalike searches that locate brand impersonation infrastructure..

Validin’s Lookalike search identifies domains that are visually or structurally similar to a specified keyword or domain. This feature helps analysts detect typosquatting, impersonation attempts, and related DNS infrastructure. Lookalike searches are performed exclusively over Validin's new domain list and are configureable with lookback of up to 90 days.

Prerequisites

Make sure you have:

  • A Validin Professional or Enterprise account
  • A keyword, brand name, or domain to search for

Execute a lookalike search

  1. Select Lookalikes from the left navigation menu.
  2. Enter a search term, keyword, domain, or regex pattern.
📘

Regex searches

To search using regex, wrap the pattern in two forward slashes, e.g.: /[0-9a-z]+/

  1. Configure Search Filters:
FilterDescriptionNotes
Excluded DomainsExcludes false-positive domainsEnter comma-separated list (e.g. ups.com, usaa.com)
LimitMaximum number of domains returnedHigher values use up more results allocation
Lookback (days)Limit results to a timeframeRange: up to 180 (default: 90)
Maximum SimilarityHow closely a result must match the inputRange: 0-4 using the Levenshtein distance
DepthDomain depth to include in the search
  • Labels (e2LDs): example[.]com
  • Subdomains (e3LDs): shop.example[.]com
  • FQDNs (any depth): a.b.c.example[.]com
👍

Exclude trusted infrastructure

To narrow your search and cut down on platform usage, specify your organization or supply chain's trusted domains in the Excluded Domains field to eliminate false-positive results.

  1. Click Search


What’s Next

Dive into the results of your Lookalike Search...

Did this page help you?