Not through a hack. Not through malware. Through something far simpler: a domain that looks almost exactly like yours.
Users mistype URLs. Employees fat-finger email addresses. Autocomplete makes wrong guesses. Mobile keyboards substitute characters. The result: sensitive communications, credentials, and traffic end up at domains that look right but aren't.
Most organisations don't know this is happening. The emails that go to the wrong domain never bounce — they just disappear into someone else's inbox.
yourcompany.org.nz instead of .co.nzThe most common confusion. A client types the right name but the wrong suffix — and their email lands in a stranger's inbox.
yourcmopany.co.nz — one wrong keyTransposed characters, doubled letters, missed keystrokes. For long or unfamiliar domain names, this happens constantly.
yourcompanyco.nz — dot droppedWhen the dot between the name and suffix disappears, the whole domain changes. It's easy to register these variants.
y0urcompany.co.nz — zero for OHomoglyph attacks swap characters that look identical in many fonts. l→1, o→0, rn→m. Often invisible to the human eye.
If a lookalike domain accepts email, someone is receiving mail intended for you. This is the single most dangerous signal.
A resolving domain means it's active. It could be serving content, redirecting traffic, or hosting a phishing page.
Who registered it? When? If it's not your organisation, someone else has claimed a piece of your identity.
What does the domain serve? A parking page is suspicious. Content mimicking your brand is an active threat.
Enter your primary domain below. We'll generate every realistic lookalike variant, probe each one for DNS, MX, and WHOIS data, and classify the risk.
MX records active, content mimicking your brand, or clear typosquatting. Immediate action required.
Registered by a third party with some active signals. Warrants investigation.
Registered but showing a generic placeholder. Likely speculative registration.
Registered and controlled by your organisation. Defensive registration working as intended.
Available for anyone to register. An opportunity to secure it proactively — or a gap waiting to be exploited.
Fuzz Security provides comprehensive domain security assessments, penetration testing, and ongoing monitoring. We help organisations across New Zealand and Australia secure their digital perimeter.