Skip to main content

Domain monitoring

Automatic detection of domains similar to yours

Updated over a month ago

The domain monitoring module automatically detects domains that resemble yours and may represent a threat of impersonation, phishing, or fraudulent redirection.

By analyzing these domains and evaluating their risk level, you can anticipate attacks and protect your organization’s reputation.


1 – Objectives

This article explains how to:

  • use the domain monitoring module within Threat Monitoring

  • understand how similar or fraudulent domains are detected

  • evaluate the risk level associated with each detected domain

  • classify domains as safe or malicious


2 – Prerequisites

  • Have access to the Threat Monitoring module

  • Have an Admin role

  • Have at least one validated domain in the platform


3 – Accessing the module

  • Go to the Threat Monitoring section

  • Click Monitoring > Domains

This table centralizes all domains identified as similar to yours.

Navigation to the Domain Monitoring section in Arsen’s sidebar, used to monitor suspicious domains.


4 – How it works

4.1 – Understanding the detection logic

The table lists all domains detected as similar to the monitored domain (selected from the menu at the top right).

Domain Monitoring list showing the monitored domain selector in the top-right corner.

4.2 – Similarity criteria

Arsen flags domains that:

  • are visually or typographically close to your domain (typosquatting)

  • match your domain but use a different extension

These domains are identified through an automatic scan performed every 24 hours.


5 – Risk evaluation

5.1 – Understanding risk factors

The risk is calculated by a provider who sends the information back to us. The criteria used to determine whether the risk is significant are numerous.

📚 Note
In addition to the information returned by our provider, it’s important to remember that the more fields a domain contains (DNS entries, records, hosting details, etc.), the higher the risk becomes.

The risk reaches its maximum when:

  • the risk is rated as high,

  • all registration informations are complete,

  • and a preview of the site is available, copying one of your landing pages.

5.2 – Risk levels

Arsen automatically assigns a level:

  • Low

  • Medium

  • High

  • N/A (no feedback from the provider, they have not enough information to calculate risk)

Domain Monitoring table highlighting the Risk column for each monitored domain.

5.3 – Types of risks identified

Social engineering risk:
Attackers can use a misleading domain to:

  • distribute phishing

  • trick employees or customers

  • replicate your legitimate pages

Reputational risk:
A malicious domain may redirect users to:

  • fraudulent sites

  • sensitive or illicit content (pornography, disturbing material)

  • malicious platforms likely to harm your brand image


6 – Classifying domains

Click the checkbox to the left of a domain row to open the action menu.

6.1 – Mark as Safe

  • Mark the domain as not presenting a risk

  • Find the domain in the Safe tab

6.2 – Mark as Malicious

  • Mark the domain as dangerous

  • Find the domain in the Malicious tab

  • Trigger a takedown procedure with authorities or registrars if necessary

Domain Monitoring table with a domain selected for Safe or Malicious classification.

Did this answer your question?