How it works
From suspicious address to evidence.
When an impersonating address appears it is seen, explained and kept reviewable. Every finding follows the same path and every step leaves a trace.
Why it shows up early.
Building a convincing fake site is cheap and fast — going live without leaving a trace is not. An impersonating address usually becomes visible before it has taken any traffic; the real work is seeing that trace in time and turning it into reviewable evidence.
Continuous monitoring
New addresses resembling your brand are seen as soon as they appear. If monitoring stops, it does not stop quietly — the panel says so.
Filtering
Look-alike impersonations are reduced to a comparable form; names that look similar but are spelled differently are caught, not dropped.
Prioritisation
Each candidate is ranked by how strong the impersonation is. The order you see starts with what you should look at first.
Visit evidence
Optional, off by default. If enabled, an anonymous report is made when a fake page is actually opened. No identity is involved.
Evidence
Source, timestamp, record reference and the reasoning behind the ranking are kept together, so a finding stays reviewable, contestable and forwardable.
Where this approach ends.
An honest method statement includes what the method cannot see.
- A site that goes live without announcing itself at all does not appear in the early signal.
- A name that does not resemble the brand at all is not flagged through similarity.
- Coverage across all issuers and logs has not been measured, so no coverage figure is published.
- Average detection time is not currently measured, so no latency figure is published.