ActorStack.dev

Finding lookalike domains by searching the zone instead of guessing them

How to run a brand sweep across 1,075 gTLDs, how to read `exact`, `typo` and `contains` differently, and why an empty result is the outcome worth paying for.

By Oswaldo Carabano7 min read

Short answer

A brand sweep over registry zone files returns every delegated domain that matches, imitates or contains a brand, across 1,075 generic top-level domains, and a match means the domain exists today rather than that it was seen once. Results arrive in three classes that deserve different treatment: `exact` is certain, while `typo` and `contains` are search rather than judgement and will surface coincidences, especially for brands under five characters. Narrowing the sweep to named TLDs makes it substantially faster and cheaper. Triage starts with `parked_for_sale`, which separates a squatter waiting to sell from a lookalike that may be running something, and a match is never by itself an infringement.

Key points

  • A brand sweep returns delegated domains that match, imitate or contain a brand across 1,075 generic top-level domains in one run.
  • A match from zone data means the domain exists today, rather than that a crawler once observed it or that it was registered at some point.
  • `exact` matches are certain, while `typo` and `contains` are search results that will include coincidences and need reading as such.
  • Brands under five characters should start at edit distance 1, because distance 2 surfaces names that share letters with a short brand purely by chance.
  • Naming the TLDs that matter makes a run substantially faster and cheaper, because the service skips the rest instead of scanning them.
  • An empty result is the outcome worth paying for and costs only the start fee, because rows are charged when they match and not otherwise.
On this page6 sections

The question is not “what could somebody register against my brand”. It is “what did they”.

Searching the zone instead of guessing names

A sweep asks the registry zone files which delegated domains match a brand, across 1,075 generic top-level domains. Because the source is the registry's own delegation record, a match means the domain exists today — not that it was registered once, and not that a crawler saw it last month.

Running a sweep

input.json — conservative first pass on a short brand
{
  "brand": ["stripe"],
  "matchTypes": ["exact", "typo"],
  "maxEditDistance": 1,
  "maxResults": 100
}

Leaving tld empty sweeps all 1,075. Naming the TLDs that matter — com, net, shop — makes the run substantially faster and cheaper, because the service skips the rest instead of scanning them.

Three match types, read three ways

TypeWhat it meansHow to read it
exactThe label is your brandCertain. Review every row
typoOne or two characters awaySearch, not judgement. Sort by edit_distance
containsYour brand inside a longer nameHighest volume, lowest precision

Choosing an edit distance

Distance 1 for a brand under five characters, distance 2 for longer ones. At distance 2 a four-letter brand collides with ordinary English words by coincidence, and a result list full of coincidences trains whoever reads it to stop reading it.

Triaging a long result list

parked_for_sale first: it fires on 2.0% of domains, it is exact when it does, and a match on a sale service is a squatter waiting to sell rather than one running a fake shop. Then dns_provider, remembering what that field can and cannot tell you.

A match is not an infringement

Note also what the sweep cannot see: country-code TLDs are outside it entirely, and they are a common home for a homograph squat.

Frequently asked questions

How do I find domains squatting on my brand?
Run a sweep with the brand as the anchor and let it search the registry zone files across 1,075 generic top-level domains. Every delegated domain whose label matches the brand, sits within an edit distance of it, or contains it comes back with its delegation.
What edit distance should I use?
Start at 1 for a brand under five characters and use 2 for longer ones. At distance 2 a short brand collides with unrelated words by coincidence, which fills the result list with rows nobody should spend time on.
How do I tell a squatter from a partner?
Start with `parked_for_sale`. A match sitting on a parking or domain-sale service is a squatter waiting to sell, which is a different problem from a lookalike on ordinary hosting. Beyond that, the judgement is a human one and the tool does not make it.
Is finding nothing a bad run?
It is the best outcome available. An empty result means nobody is squatting on the brand in the zones covered today, and it costs only the start fee because rows are charged when they match and not otherwise.

Sources

Every URL below was requested and returned a page on the date shown.

  1. Operator claimchecked 18 Sept 2026
    Typosquatting Detection — Actor README and input schemaActorStack / Apify Store
  2. Law or regulatorchecked 18 Sept 2026
    Uniform Domain-Name Dispute-Resolution PolicyICANN
  3. Platform docschecked 18 Sept 2026
    Centralized Zone Data ServiceICANN
A laptop screen showing a plain text-mode terminal with a command prompt.
DomainsComparison

dnstwist versus zone search

Permutation engines find the squats their rules predicted. Searching the registry zone finds what is actually registered, including the spellings no generator would produce — and each approach misses something the other catches.

6 min
A row of residential mailboxes on posts in front of a wooden fence and trees.
DomainsGuide

Detecting domain hijacking

Whoever controls the nameservers controls the mail, the site and the certificates. That change happens in the registry zone, which is the one layer most monitoring never looks at.

7 min
A white shuttered window on a peach-coloured building with a for-sale notice beside it.
DomainsGuide

Bulk availability without WHOIS

Screening a naming shortlist against zone files instead of querying WHOIS per name: what it costs, what the verdicts mean, and where the method stops being enough.

7 min