What Does Brand Protection Provide?
Brand Protection continuously monitors the internet for lookalike domains that impersonate your brand. When a lookalike is discovered, CanIPhish tracks it as a case, watches it for signs of weaponisation, safely captures and AI-analyses any live content it serves, and helps you file takedown requests with the responsible registrar or hosting provider — all from a single view within the CanIPhish platform.
Attackers register lookalike domains to phish your employees, your customers and your suppliers. Most lookalikes sit dormant for weeks before they're used, which is exactly the window Brand Protection is designed to exploit: you find out when the domain appears, not when the first phishing email lands.
Table of Contents
- How Does Brand Protection Work?
- Requesting Takedowns
- Notifications
- Getting Started
- Frequently Asked Questions
How Does Brand Protection Work?
Brand Identifiers
Everything starts with your brand identifiers — the things every detection is matched against. Two types are supported:
- Domains: Protect a domain you own. Domain identifiers are chosen from the domains you've verified ownership of within CanIPhish, and detections cover lookalikes of that domain — typosquats, homoglyphs, alternate TLDs and similar variations. Up to 50 domain identifiers can be configured.
- Keywords: Protect a brand name or product name as a free-text term. Keyword identifiers catch lookalikes that a domain identifier alone wouldn't, such as your brand name combined with words like "login" or "support" under any TLD. Up to 100 keyword identifiers can be configured.
Note: Keywords that may match too broadly (for example, short or generic terms) are flagged during setup. You can still add them, however, they'll be held for review by CanIPhish before monitoring starts, and you'll be emailed once the review is complete.
Detection Sources
CanIPhish discovers lookalike domains through multiple independent sources:
- Certificate Transparency: Every newly issued SSL/TLS certificate on the internet is published to public certificate transparency logs. CanIPhish monitors these logs continuously and matches every new hostname against your brand identifiers — often surfacing a lookalike within minutes of the attacker requesting their first certificate.
- TLD Zone Files: CanIPhish ingests daily zone file data from ICANN's Centralized Zone Data Service, covering the authoritative list of registered domains across participating top-level domains. This catches lookalikes at the moment of registration — before any certificate is requested and before any content is served — including domains that never obtain a certificate at all.
- Domain Permutations: Common typosquats, character swaps and TLD variations of your domain identifiers are generated and checked for registration.
- Phishing Threat Feeds: Known-malicious domains from phishing intelligence feeds are swept for matches against your identifiers.
- Employee-Reported Emails: If you use Phish Triage, URLs within the emails your employees report are also checked against your brand identifiers.
Additional discovery sources are being added throughout the beta period.
The Case Lifecycle
Each detection becomes a case, and every case is re-checked automatically — live threats are re-checked as often as every six hours. As a lookalike domain builds out infrastructure, its case moves through states that describe what the domain is currently doing:
- Detected: The lookalike has been discovered but isn't resolving to anything yet.
- Parked: The domain resolves to a domain-parking service.
- Dormant: The domain previously resolved but has since gone quiet.
- Nameservers Changed: The domain has been pointed at real infrastructure.
- Mail Records Added: The domain has mail (MX) records — it can now send email that appears to come from the lookalike.
- Certificate Issued: An SSL/TLS certificate has been issued for the domain.
- Live Content: The domain is serving a live web page.
- Credential Harvesting: The domain is serving a page with a credential-capture form — the most weaponised state.
Each case carries a severity of Critical, High, Medium or Low, derived from how weaponised the domain currently is. Severity moves with the case: a dormant lookalike that suddenly starts serving a credential-capture page escalates automatically, and escalations can trigger alerts (see Notifications below).
AI-Powered Page Analysis
When a case begins serving live content, CanIPhish loads the page inside an isolated sandbox — never from your network — captures a screenshot, and has an AI analyst examine what the page actually is. The AI assesses whether the page impersonates your brand, whether it's harvesting credentials, and produces a plain-language verdict with one of three recommendations:
- Takedown Suggested: The page looks like genuine brand impersonation and is worth acting on.
- Keep Monitoring: Nothing actionable yet, but the case is worth watching.
- Likely Not A Threat: The page appears to be unrelated to your brand — for example, a legitimate business whose name coincidentally matches.
The verdict appears in the AI Analysis column of the Active Cases table, and the full rationale — including the captured screenshot and a suggested course of action — is available within the case detail view. Detections are also cross-referenced against the APWG eCrime Exchange, an industry threat-intelligence exchange, so you can see when a lookalike has been independently reported as malicious.
Requesting Takedowns
When a case warrants action, a takedown request can be raised directly from the case detail view. CanIPhish automatically assembles the supporting evidence — the registrar and hosting provider's abuse contacts, the captured screenshot, DNS and registration details, and any corroborating threat intelligence — and every request is reviewed by a person before it goes, with the outcome reported back to you.
Before the first takedown request can be raised, an administrator must complete a one-time authorisation confirming your organisation's legal name. This authorises CanIPhish to report brand infringement on your organisation's behalf.
The Takedown Requests counter at the top of the Brand Protection page tracks how many requests have been raised across all of your cases, and each case shows the current status of its latest request.
Notifications
Notification preferences are configured within Brand Protection Settings:
- Alert Severity: Choose which severities generate an email alert. A case alerts when it reaches an enabled severity — so with High enabled, you're emailed the moment any case escalates to High.
- Recipients: Add the email addresses that should receive alerts.
- Takedown Filings: Optionally receive an email whenever a takedown report is filed, including where it was sent.
Getting Started
- Log in to the CanIPhish platform, click the 3 dots to expose all Threat Analysis features, and toggle on Brand Protection.
- Open Brand Protection Settings. If you haven't configured any identifiers yet, the settings window opens automatically.
- On the Identifiers tab, add the domains and keywords that identify your brand.
- On the Notifications tab, choose your alert severities and recipients.
- Optionally, review the Analysis tab (page analysis preferences), the Takedowns tab (takedown authorisation) and the Allowlist tab (exempt known-good domains from detection).
That's it — monitoring begins immediately. New detections appear in the Active Cases table automatically as they're discovered, and the empty table shows live scanning statistics so you can see monitoring working before your first detection arrives.
Frequently Asked Questions
Which Subscription Includes Brand Protection?
Brand Protection is included with Enterprise subscriptions at no additional cost.
What Happens If A Detection Isn't Actually A Threat?
Some detections turn out to be legitimate businesses with coincidentally similar names — the AI analysis will typically flag these as "Likely Not A Threat". You can close the case as Not A Threat, which prevents it from reopening, or add the domain to your Allowlist to stop it (and matching patterns) from being detected again.
Do I Need To Do Anything For Monitoring To Run?
No. Once identifiers are configured, discovery and case re-checking run continuously and automatically. You only need to act when a case is worth a takedown — and alerts will tell you when that moment arrives.
Are Lookalike Pages Ever Loaded From My Network?
No. All page captures and AI analysis happen inside an isolated CanIPhish sandbox environment. Your network never touches the suspicious infrastructure.
Comments
0 comments
Please sign in to leave a comment.