Brand Protection
Find the domains trading on your brands, have each one assessed for risk, and decide what to do about it.
Brand Protection finds domains that trade on your brands but are not yours — lookalike registrations, copycat shops, phishing pages and parked squats. For each one it fetches what the domain serves, has an AI model assess the risk, and hands you a ranked queue to work through: watch it, flag it, raise a Jira ticket, or ignore it with a reason.
It sits in the sidebar directly below Inventory, and it is woven into the rest of the product: findings share the Review Pipeline with DNS issues, the dashboard carries a Brand Protection card, the Zones table counts copycats per zone, and detections reach your notification channels.
How it works, in one pass
your brands → web search + certificate logs + due re-checks
→ DNS resolution → page fetch → AI risk assessment
→ screenshots → notifications → your triage- Discovery starts from your brands — the ones you register on the Brands page and the ones DNS Watchdog infers for your zones — and searches the web for domains that contain them, adds domains seen in certificate transparency logs and any you add by hand, and re-checks known findings on a schedule. See Discovery.
- Assessment fetches each live page and asks an AI model how similar the name is, how far the page passes itself off as your brand, how commercially it exploits it and whether it is malicious, producing a 0–100 risk score and a classification. See Risk assessment.
- Triage happens on the Brand Protection page — a flat list, highest risk first, with a slim detail view built for working a queue — or from the Review Pipeline, where findings sit beside DNS issues. See Reviewing findings.
Everything runs once a day, automatically, and every priced step is bounded: search pages per brand, page fetches per run, model calls per day. See Runs and limits.
Getting started
- Register your brands. Open Brands under Inventory. DNS Watchdog will already have inferred a brand for most of your zones; confirm those, merge duplicates, and add any brand that has no zone of its own. Every brand on that page is searched.
- Wait for the daily run. Discovery runs each day at 04:00 UTC. The first run searches every brand, so it takes longer than the routine ones; Run statistics on the Brand Protection page shows what it did.
- Work the queue. New findings arrive as Pending review, highest risk first. The Details view puts the list beside an inspector: read the verdict and the model's reasoning, look at the screenshot, and set the status from the decision bar — or raise a Jira ticket in one click. The Board view shows the same findings as cases in status columns.
Brand Protection is enabled per environment by DNS Watchdog; the web-search and AI capacity behind it are shared and metered, which is why every step carries a bound.
What a finding is
A finding is one domain, in your organisation, that discovery matched to one or more of your brands. It carries:
| Part | What it holds |
|---|---|
| Identity | The domain, the brands it trades on, the zones of yours it resembles, and how it was found (web search, certificate log) |
| Liveness | Whether the domain resolves and serves a page (serving, dormant, unresolved, offline), and whether it publishes mail records |
| Page snapshot | The fetched page's HTTP status, title, description, a text excerpt, its outbound links and redirect chain, plus a screenshot |
| Assessment | The model's scores, threat types, site status, classification, confidence and reasoning — or, while the model is unavailable, a deterministic fallback that keeps the finding hidden until the model scores it |
| Triage | Its status (Pending review, Watching, Flagged, Ignored), who last changed it and when, the reason if ignored, a linked Jira ticket, and the notes reviewers have left |
Findings below the risk floor, and findings the model has not yet scored, are kept — so the same page is never assessed twice — but hidden from every view unless asked for. A domain you have ignored is never scanned or raised again.
Pages in this section
- Discovery — where candidates come from and how they are narrowed to live pages
- Risk assessment — what the model scores, the classification bands, the risk floor and the fallback
- Reviewing findings — the four views, filters, the detail view, the finding page, statuses, Jira tickets and export
- Review Pipeline — findings beside DNS issues, the dashboard card and the Zones column
- Notifications — when a finding notifies and what the changelog records
- Roles and access — what each role can do, and the Brand Protection role
- Runs and limits — the daily run, run statistics and every bound