Spot fake lookalike domains targeting your brand automatically

The system scans new SSL certificates for domains that mimic your brand and alerts you with a screenshot before customers get tricked.

How the work actually flows

It repeats. Repeats scan not finished yet; runs once per each suspicious domain found.

Pattern: Structured Loop (21) ยท Multiple Instances with a priori Design-Time Knowledge (13)

flowchart TD trig(["hourly certificate check"]):::trigtime s0[["screenshot suspicious domain"]]:::mi s1["request urlscan scan"]:::svc s2["check scan status"]:::task s3["send slack alert"]:::svc trig --> s0 s0 --> s1 s1 --> s2 lp{"scan completes"}:::gate s2 --> lp lp -. "scan not finished yet" .-> s1 lp -->|"finished"| s3 out[/"slack alert with proof sent"/]:::out pay{{"catches phishing domains early"}}:::pay s3 --> out out --> pay classDef task fill:#e7f6fe,stroke:#34b8f0,color:#2c2a29 classDef svc fill:#f6f8fa,stroke:#7c8795,color:#2c2a29 classDef mi fill:#e7f6fe,stroke:#0079a8,color:#2c2a29,stroke-width:2px classDef human fill:#fff,stroke:#0079a8,color:#0079a8 classDef store fill:#f6f8fa,stroke:#0079a8,color:#2c2a29 classDef trig fill:#00a4eb,stroke:#0079a8,color:#fff,font-weight:bold classDef trigtime fill:#00a4eb,stroke:#0079a8,color:#fff,font-weight:bold classDef trigdata fill:#8ad4f5,stroke:#0079a8,color:#06314c,font-weight:bold classDef gate fill:#fff,stroke:#e8a23d,color:#6b4708,font-weight:bold classDef out fill:#1f9d6b,stroke:#167a53,color:#fff,font-weight:bold classDef pay fill:#06314c,stroke:#021f33,color:#fff
Starts itA stepAn outside serviceRuns once per itemRepeat or finishResultPayoff
Build size
Advanced

A larger build with multiple systems, AI reasoning, and custom rules.

Business functions
Messaging & Notifications
Connects
crt.shUrlscan.ioSlack

The problem it solves

Someone could be registering a domain that looks almost exactly like yours right now, and you'd have no way of knowing until a customer gets fooled by it. Checking certificate logs and scanning suspicious sites by hand isn't something your team has time to do every hour.

Who it fits

Businesses with a recognizable brand or login page that are a target for phishing and impersonation scams.

How it works

  1. Every hour, the system checks crt.sh for new SSL certificates matching your brand name
  2. Suspicious domains are automatically screenshotted and scanned by Urlscan.io
  3. The system waits for the scan to finish, then pulls the results
  4. A Slack alert is sent with the domain, a report link, and a screenshot of the site
What you get

Phishing domains you spot before customers do

You get an alert with a screenshot and report the moment a lookalike domain targeting your brand shows up online.

What you get

A Slack alert flagging suspicious lookalike domains with visual proof.

What you need

An Urlscan.io account and a Slack workspace.

We can build this. But should you?

The hard question is not how to build it. It is whether this is the right thing to build first.

That is what a Fractional Chief AI Officer figures out with you, before anyone writes a line of code.

Let's Talk Strategy

Related automations

Back to the AI Playbook