Cybersecurity

What is a TLD Enumerator and Why Would I Use It?

A TLD enumerator takes your brand name and checks it across every top-level domain at once, so you can find cybersquatters and lookalike registrations before they harm customers.

By Inventive HQ Team

A TLD enumerator is a tool that takes one brand name — the second-level label like "acme" — and checks it across every top-level domain at once (acme.com, acme.net, acme.io, acme.co.uk, acme.app, and hundreds more), reporting which are registered and which are still available. Instead of running WHOIS by hand against a few extensions, you get the full picture of where your name lives across the domain namespace in a single query. Security and brand teams use it to find the lookalike domains a cybersquatter or phisher has already grabbed, and the gaps a competitor or attacker could still register.

That's the summary an AI Overview would give you. Here's what it can't show you — the actual fan-out of one label across the 1,500+ TLDs in the IANA root zone, a priority table for deciding which extensions are worth defending, and the live enumerator itself so you can run your own brand right now.

The core idea: one label, every extension

Every domain name has two parts that matter here: the label you chose (your brand) and the top-level domain it sits on (the extension after the final dot). TLD enumeration holds the label constant and sweeps it across the extension space. The diagram below shows what that looks like for the label acme — the same name resolving to very different owners and very different risks depending on the TLD.

One brand label enumerated across many top-level domains A central label "acme" connects outward to eight top-level domains, each tagged as owned by you, available to register, or already taken by someone else. TLD enumeration: fix the label, sweep the extensions acme your label acme.com owned by you acme.net owned by you acme.app available — gap acme.io available — gap acme.co taken by other acme.xyz taken by other acme.co.uk taken by other acme.shop available — gap you own it open gap someone else

The two red chips on the right (acme.co, acme.xyz, acme.co.uk) are the reason enumeration exists. Each one is a domain someone else can point at a lookalike site, use to send convincing phishing email, or hold for ransom. You cannot fix what you cannot see, and no team manually WHOIS-checks 1,500 extensions.

Run it on your own brand

The enumerator below is the live tool — type your label, and it sweeps the extensions and shows you registered-versus-available across the TLD space. Nothing to install.

Loading interactive tool...
Advertisement

TLD enumeration vs. typosquatting checks

These two techniques get conflated constantly, and using only one leaves half your attack surface unmonitored. The difference is simply which part of the domain you hold constant.

TLD enumerationTyposquatting check
What stays fixedThe label (acme)The extension (.com)
What variesThe TLD (.com.io.co.uk)The label (acmeacmee, acrne)
CatchesYour exact name on other extensionsLook-alike/mistype versions on your extension
Example threatSquatter registers acme.app you never boughtAttacker registers acrne.com for phishing
Primary toolTLD enumeratorTyposquatting / homoglyph checker
Which should I use?Both — attackers combine them (a typo on a new gTLD). Enumerate to map extensions, then run typo/homoglyph checks on your primary domains.

For the label-variation side of that pairing, see protecting your brand from typosquatting and homoglyph and homophone squatting detection.

Which extensions actually deserve defensive registration

You do not need to buy your name on all 1,500+ TLDs — that is a budget trap registrars love to sell. Enumeration's real job is to triage: register the few that matter, monitor the rest. Here's how to rank what enumeration surfaces.

PriorityTLD groupWhy it mattersAction
Critical.com + your ccTLDs (.uk, .de, .jp per market)Highest customer trust; direct type-in trafficRegister and renew defensively
HighIndustry-match gTLDs (.app, .shop, .io, .bank)Plausible enough to fool customersRegister the ones tied to your product
MediumCheap high-abuse gTLDs (.xyz, .top, .click)Common in phishing kits; low cost to squatMonitor; register only if actively abused
LowObscure/irrelevant gTLDsLow impersonation valueMonitor via enumeration; act on abuse only

Our deeper guide on priority TLDs for brand protection breaks down the shortlist market by market.

From enumeration to action

Enumeration is the first step in a chain, not the whole answer. The workflow that turns a list of registered variations into actual protection looks like this:

Brand-protection workflow from enumeration to takedown Four steps flow left to right: enumerate all TLDs, run WHOIS on registered ones, classify each as owned, benign, or malicious, then register gaps or file a UDRP complaint. 1. Enumerate sweep every TLD 2. WHOIS / RDAP who registered it? 3. Classify yours / benign / bad 4. Register / UDRP close gaps, escalate

Step 2 is where enumeration hands off to the WHOIS database (or its modern successor, RDAP): enumeration tells you a domain is taken; WHOIS tells you by whom, when, and through which registrar. See understanding WHOIS data for reading those records, and the cybersquatting prevention guide for the legal escalation path.

What enumeration can't do

Be honest about the limits so you don't over-trust the output:

  • It confirms registration, not intent. A registered acme.io might be a partner, a reseller, or a squatter. Classification still needs a human plus WHOIS.
  • It doesn't cover subdomains or paths. login-acme.attacker.com won't appear — that's a different detection problem.
  • Availability is a snapshot. A domain "available" today can be grabbed tomorrow, which is why enumeration belongs on a recurring schedule, not a one-off audit.
  • Owning a domain isn't the same as securing it. Even domains you register need proper DNS hygiene — see why DNSSEC matters for hardening the ones that matter.

Bottom line

A TLD enumerator collapses "check my brand everywhere" into a single sweep across the DNS namespace, turning an invisible attack surface into a triage list. Run it, WHOIS the registered hits, register the extensions that carry real impersonation risk, and monitor the rest on a schedule. Start with your own brand in the TLD Enumerator above, then work down the priority table.

Frequently Asked Questions

What is a TLD enumerator?

A TLD enumerator is a tool that takes a single second-level label (for example, "acme") and generates the same name across many top-level domains — acme.com, acme.net, acme.io, acme.co, acme.co.uk and so on — then reports which are registered and which are still available. It turns "check my brand across every extension" from hours of manual WHOIS lookups into one query.

Why would I run TLD enumeration for my brand?

Because attackers register your brand on extensions you never bought. A company that owns example.com but not example.co or example.app leaves an open door for a cybersquatter to stand up a lookalike site, send phishing email from a convincing address, or resell the domain back to you at a markup. Enumeration shows you the full attack surface in one view.

How many TLDs are there to check?

The IANA root zone contains more than 1,500 top-level domains — roughly 300 country-code TLDs (like .uk, .de, .jp) and over 1,200 generic TLDs (.com, .app, .xyz, .shop, and hundreds more). No human checks all of them by hand, which is exactly why enumeration is automated.

Is a TLD enumerator the same as a typosquatting checker?

No, though they overlap. A TLD enumerator keeps the label fixed and varies the extension (acme.com to acme.io). A typosquatting checker keeps the extension and varies the label (acme.com to acmee.com, acrne.com). Serious brand protection uses both, because attackers combine the two — acme.io with a swapped character is a common pattern.

Which TLDs should I prioritize protecting?

Start with .com, your ccTLDs in every market you operate in, and the handful of extensions that match your industry (.app for software, .shop for retail, .bank/.insurance where eligible). Then cover cheap high-abuse extensions frequently used in phishing (.xyz, .top, .click). You do not need to defensively register all 1,500 — you need to monitor them and own the ones that matter.

Does enumeration tell me who owns a registered domain?

Enumeration tells you a domain is registered; WHOIS or RDAP tells you who registered it. The normal workflow is enumerate first to find every taken variation, then run WHOIS/RDAP on the suspicious ones to see registration dates, registrar, and any contact details GDPR redaction has not hidden.

Can I take down a domain a squatter registered with my brand?

Sometimes. If the registration is a bad-faith copy of a trademark you own, the UDRP (Uniform Domain-Name Dispute-Resolution Policy) lets you file a complaint to transfer or cancel it. Enumeration is the evidence-gathering step — it documents exactly which lookalike domains exist before you escalate to legal or registrar action.

How often should I re-run TLD enumeration?

Treat it as monitoring, not a one-time audit. New gTLDs launch, squatters register opportunistically after product announcements, and ICANN's next new-gTLD application round is expected to add more extensions. Re-checking monthly — or after any launch, funding announcement, or rebrand — catches new registrations while a UDRP or takedown is still cheap.

TLD enumerationdomain securitybrand protectioncybersquatting