Generate your brand across 150+ TLDs and check which are already registered, with registrar and expiry dates. Export TXT, CSV or JSON for free.
Enter a domain and this tool generates the same name across more than 150 top-level domains, then checks which of those are already registered. You get a grouped list — legacy generic TLDs, country codes, new gTLDs, and sponsored TLDs — with registration status, registrar, creation date, and expiry date for each one you check. Copy the list, or export it as TXT, CSV, or JSON for a brand-protection register.
This is a defensive exercise. If your company owns example.com and someone else has quietly registered example.net, example.co, and example.support, you want to know that before a customer receives an invoice from one of them. Enumerating the extensions is how you find out what exists, who registered it, and when.
https://www.example.com/pricing becomes example..bank, typing “Germany” finds .de.One thing it deliberately does not do: it does not mutate the name itself. It varies the extension only, so example.com produces example.net and example.io, not exarnple.com or exampel.com. Character-level typosquat generation is a separate exercise — see the note below on covering both.
| Type | Count | What it covers |
|---|---|---|
| Legacy generic | 7 | .com, .net, .org from 1985, plus .info, .biz, .name, .pro from the early 2000s. |
| Country code (ccTLD) | 62 | Two-letter codes assigned per territory: .uk, .de, .jp, .au, .br. Some are effectively generic through repurposing. |
| New gTLD | 74 | The 2012-onward expansion: .app, .dev, .shop, .online, .xyz, .cloud and many more. |
| Sponsored | 8 | Restricted extensions with an eligibility requirement, such as .gov, .edu, .mil, and .bank. |
The categories matter because they carry different levels of risk. Sponsored TLDs are the safest: nobody is registering yourbrand.bank to defraud your customers unless they can satisfy a financial-institution verification process. Restricted extensions are flagged in the database so you can see which ones are gated.
Country codes are the subtlest trap. Several are repurposed as generic-looking extensions — .co (Colombia) reads as an abbreviation of “company” and is one character from .com, .io (British Indian Ocean Territory) became a technology convention, .ai (Anguilla) followed the same path. Those blend in well enough that a customer glancing at a sender address rarely notices. Meanwhile registering in a ccTLD you do not operate in may be governed by local presence rules, which cuts both ways: it constrains you, and it constrains an impersonator.
New gTLDs are where volume lives. There are well over a thousand of them, several priced low enough to be disposable, and they supply the semantic half of a convincing lure — yourbrand.support, yourbrand.security, yourbrand.billing. Those read as plausible corporate subdomains to someone who is not looking closely, which is precisely the point of them.
Finding a registered lookalike is not by itself evidence of wrongdoing. Before escalating, gather:
Where the evidence supports it, the remedies are the registrar abuse process, a UDRP or URS complaint through ICANN’s dispute procedures, and takedown requests to the hosting provider. Where it does not, the sensible response is usually to register the handful of extensions that would be most convincing in an attack and move on — defensive registration of every plausible extension is neither affordable nor necessary for most organisations.
A workable budget rule: buy the legacy generics, the ccTLDs for countries where you actually trade, and any new gTLD that matches a function your customers would believe (.support, .shop, .app if you ship one). Monitor the rest rather than owning it. Monitoring is what the quarterly export and diff is for.
Remember also that extension-swapping is only one class of lookalike. The others are character substitution (rn for m, 1 for l), homograph attacks using visually identical Unicode characters from other scripts, hyphenation (your-brand.com), and combosquatting (yourbrand-login.com). A complete programme covers all of them; this tool covers the extension axis thoroughly and should be paired with tooling for the others.
Look up full registration records for a specific domain with the WHOIS lookup, check for character-level lookalikes and mail-authentication weaknesses with the domain spoofing detector, find issued certificates and hidden subdomains through the certificate transparency lookup, and inspect the DNS records of anything suspicious with the DNS lookup tool.
No. It varies the extension while keeping the name intact — example.net, example.io, example.shop. Character-level typosquats such as exampel.com are a different technique; use the domain spoofing detector alongside this for that axis.
151 in the built-in database: 7 legacy generic, 62 country-code, 74 new gTLDs, and 8 sponsored. That is a curated set of the extensions that matter most for brand protection, not the full list of over a thousand delegated TLDs.
It queries registration data for each domain and reports registered or available with the registrar and dates where they are published. Results may be served from a short-lived cache, which is indicated on the result. Some registries publish limited data, and privacy services mask registrant details, so treat “registered” as reliable and the accompanying detail as best-effort.
Almost certainly not — the cost scales badly and the coverage is never complete. Register the legacy generics, the country codes for markets you trade in, and the few new gTLDs that would be genuinely convincing in an attack against your customers. Monitor the remainder.
Yes. Generating name variations is arithmetic, and registration data is published by design so that domain ownership is accountable. This is the same information a trademark attorney or a brand-protection service would gather, and the intended use here is defensive.
Gather evidence first: creation date, whether it resolves, whether it serves imitative content, and whether it has mail records. Then use the registrar’s abuse process, a UDRP or URS complaint if you hold trademark rights, or a hosting takedown request. A registration alone, with no infringing use, is a weaker case than one backed by a copied login page.
Because several registries market them that way. .co is Colombia, .io is the British Indian Ocean Territory, .ai is Anguilla, .tv is Tuvalu. Their generic appearance is exactly what makes them effective for impersonation, so they deserve attention even if you have no presence in those territories.
Domains with fewer than 30 days remaining are highlighted. For your own domains that is a renewal reminder. For a lookalike it may signal an abandoned registration that is about to drop — which is either an opportunity to acquire it or a warning that someone else will.
Yes — TXT, CSV, or JSON, plus clipboard copy for individual domains or the whole list. CSV is the practical choice for keeping a quarterly baseline you can diff.
Quarterly is a reasonable cadence for most organisations, and immediately after any event that raises your profile: a funding round, a product launch, an acquisition, or a breach disclosure. Those are the moments when opportunistic registration of your name spikes.
TLD (Top-Level Domain) enumeration discovers all domain registrations associated with a base name across different top-level domains — checking whether example.com, example.net, example.org, example.io, example.co, and hundreds of other TLDs are registered and by whom. This technique is essential for brand protection, security assessment, and domain portfolio management.
With over 1,500 TLDs available (including gTLDs like .com, .org, .io and ccTLDs like .uk, .de, .jp), organizations cannot realistically register their brand across all of them. TLD enumeration identifies which variations are already registered, potentially by competitors, domain squatters, or threat actors preparing phishing campaigns.
| Type | Examples | Count | Registration |
|---|---|---|---|
| Generic (gTLD) | .com, .net, .org, .info | ~1,200+ | Open to anyone |
| Country Code (ccTLD) | .uk, .de, .jp, .au, .ca | ~300+ | Some restricted to residents |
| Sponsored (sTLD) | .edu, .gov, .mil, .museum | ~15 | Restricted eligibility |
| New gTLD | .tech, .cloud, .security, .app | ~1,000+ | Open (most) |
| Infrastructure | .arpa | 1 | Technical use only |
TLD enumeration checks domain availability across multiple top-level domains (TLDs). Example: checking example.com, example.net, example.org, example.io, etc. Used for: brand protection (register variants before squatters), typosquatting detection (find malicious lookalikes), reconnaissance (discover company assets), domain availability research. 1,500+ TLDs exist: generic (.com, .net), country-code (.uk, .de), new gTLDs (.app, .dev). Automates manual WHOIS checks.
Protects brand from: typosquatting (malicious lookalikes), cybersquatting (trademark domains), phishing (fake login pages), reputation damage. Attackers register similar domains with different TLDs to trick users. Example: paypal.com (real) vs paypal-secure.net (phishing). Defensive registration: buy important TLD variants before attackers. Cost-effective: prevent customer confusion, legal disputes, incident response. Monitor registered variants for suspicious activity (email spoofing, malware hosting).
Priority TLDs for brand protection: .com (commercial, most trusted), .net (network/tech), .org (organization), country-codes (.co.uk, .de, .ca where you operate), .io (tech startups), .app/.dev (applications), .ai (AI companies). New gTLDs: .tech, .online, .store, .cloud. Typosquatting risks: .cm (typo of .com), .om, .co. Register: primary TLD + major variants + country TLDs. Monitor rest for infringement.
Typosquatting detection techniques: 1) Homograph attacks (unicode lookalikes: apple.com vs аpple.com). 2) Character substitution (paypal → paypai, google → gooogle). 3) TLD variations (example.com → example.net). 4) Transposition (faceboook). 5) Omission (gogle). Tools: dnstwist, URLCrazy. Monitor: newly registered domains, SSL certificate transparency logs. Response: UDRP complaint, legal action, takedown requests. Prevention: defensive registration, trademark monitoring, DMARC for email.
Domain availability checking queries domain registration status. Methods: 1) WHOIS lookup (shows registrant, dates, nameservers). 2) DNS query (registered domains have nameservers). 3) HTTP request (active websites respond). Rate limits: WHOIS servers limit queries (1-10/second). Bulk checking: use RDAP (Registry Data Access Protocol), commercial APIs (DomainTools, WhoisXML). Available = unregistered, can purchase. Registered = check expiration date, monitor for release.
As of 2025: 1,500+ TLDs. Categories: Generic (gTLDs) - .com, .net, .org (~1,200 new gTLDs after ICANN expansion 2013). Country-code (ccTLDs) - .uk, .de, .jp (~250). Sponsored (sTLDs) - .edu, .gov, .mil. Infrastructure - .arpa. New gTLDs: .app, .dev, .cloud, .tech, .shop. Most popular: .com (40% of domains), .tk (free Tokelau ccTLD), .cn (China), .de (Germany). Source: IANA Root Zone Database.
UDRP is ICANN policy for resolving domain disputes without litigation. Applies to: .com, .net, .org, many new gTLDs (not all ccTLDs). File complaint if domain: 1) Identical/confusingly similar to your trademark. 2) Registrant has no legitimate rights. 3) Registered/used in bad faith (resale, disruption, phishing). Process: online complaint, respondent reply, panelist decision (45-60 days). Remedies: transfer domain, cancel registration. Cost: $1,500-3,000. Alternative: legal action (more expensive/slower).
Monitoring automation: 1) Certificate Transparency logs (crt.sh API) - new SSL certificates issued. 2) WHOIS history APIs (DomainTools, SecurityTrails) - registration changes. 3) DNS monitoring (passive DNS feeds) - newly active domains. 4) Brand monitoring services (Bolster, MarkMonitor). Alerts for: new registrations matching brand, expired domain availability, DNS changes, SSL certificates. Integrate with: SIEM, ticketing systems, threat intel platforms. Check daily for high-value brands, weekly for general monitoring.