Skip to main content
The domain type represents lookalike or typosquatted domains identified by Flare’s detection engines, often leveraging tools such as dnstwist.
These records capture information about suspicious domains that closely resemble legitimate organizations’ domains and could be used in phishing, brand impersonation, or malware campaigns.
The domain event is also referred to as the discovery event: it is emitted when a lookalike domain is first discovered. It is complemented by the domain_* enrichment events documented below, which each carry the results of one enrichment (page title, IP addresses, favicon, screenshot, DNS records, WHOIS/RDAP data, SSL certificates) and reference the discovered domain through their domain field.
Some of the below field types will not be available until after August 26th.

domain

Example Content

domain_title

The page title observed on the lookalike domain.
Example Content

domain_ip_address

The IP addresses the lookalike domain resolves to.
Example Content

domain_favicon

The favicon observed on the lookalike domain.
Example Content

domain_screenshot

A screenshot of the lookalike domain’s landing page.
Example Content

domain_dns_records

The DNS records observed for the lookalike domain.
Example Content

domain_whois_rdap

Registration data for the lookalike domain, collected from both WHOIS and RDAP.
Example Content

domain_certificate

An SSL certificate observed covering the lookalike domain.
Example Content