# Domain Typosquatting & Phishing Detector (dnstwist) (`ntriqpro/dnstwist-osint`) Actor

Find registered look-alike domains (typosquatting, homoglyphs, TLD swaps) impersonating your brand — powered by the open-source dnstwist engine. Public DNS data only. For brand protection and authorized security research.

- **URL**: https://apify.com/ntriqpro/dnstwist-osint.md
- **Developed by:** [daehwan kim](https://apify.com/ntriqpro) (community)
- **Categories:** Developer tools, Business
- **Stats:** 18 total users, 11 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$30.00 / 1,000 registered domain founds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## Domain Typosquatting & Phishing Detector (dnstwist)

Find **registered look-alike domains that impersonate your brand** — typosquatting, homoglyph (IDN) spoofs, TLD swaps, bitsquatting, and more — powered by [dnstwist](https://github.com/elceef/dnstwist) (Apache-2.0), the industry-standard domain permutation engine. The Actor generates thousands of permutations of your domain and resolves **which ones are actually registered**, so you see the real phishing and brand-impersonation threats instead of a noisy wordlist.

Built for **brand-protection teams, security analysts, fraud investigators, and SOC/CTI teams** who need to monitor domain abuse with zero setup. Public DNS data only — this Actor never logs into or scrapes the content of any target domain.

> **Legal Disclaimer:** This Actor is an unofficial integration of dnstwist (elceef/dnstwist) and is not affiliated with or endorsed by the original project. It uses publicly available DNS data for defensive brand-protection and authorized security research. Comply with all applicable laws in your jurisdiction.

***

### What does this Actor do?

Give it a domain (e.g. `yourbrand.com`) and it will:

1. Generate thousands of **permutations** — typos, character swaps, missing/added letters, homoglyphs (e.g. `yourbrаnd.com` with a Cyrillic "а"), hyphenation, TLD substitutions (`.com` → `.net`, `.co`, ...), and bitsquatting.
2. Resolve each permutation's **live DNS records** (A, AAAA, MX, NS).
3. Return the ones that are **actually registered** — the genuine impersonation risk — including whether they have a **mail server (MX)**, which signals possible phishing-email capability.

Running on Apify gives you scheduling, a REST API, dataset exports (JSON/CSV/Excel), and monitoring — so you can watch for newly registered look-alikes on a recurring schedule.

### Why use this Actor?

- **Brand protection** — discover domains squatting on your brand before customers get phished.
- **Anti-phishing** — `hasMailServer` flags look-alikes configured to *send* email (the dangerous ones).
- **M\&A / due diligence** — map the domain footprint and impersonation exposure of any company.
- **Continuous monitoring** — schedule weekly scans to catch newly registered copycats.

### How to use it

1. Enter your **domain** (just the domain, e.g. `example.com` — no `http://`, no path).
2. Leave **Registered domains only** on to see just the real threats (recommended).
3. Run it. Each registered look-alike becomes one row in the dataset.
4. Export to CSV/JSON/Excel or pull via the API. Schedule it for ongoing monitoring.

### Input

| Field | Type | Description |
|---|---|---|
| `domain` | string | The domain to protect, e.g. `example.com`. **Required.** |
| `registeredOnly` | boolean | Only return permutations that actually resolve (default `true`). |
| `maxResults` | integer | Cap on look-alikes returned/charged (default 200, max 500). |
| `timeout` | integer | Max scan time in seconds (default 300). |

### Output

Each registered look-alike domain is one dataset record. You can download the dataset in JSON, HTML, CSV, or Excel.

```json
{
  "inputDomain": "example.com",
  "variantDomain": "example.com",
  "fuzzer": "omission",
  "registered": true,
  "hasMailServer": true,
  "dnsA": ["203.0.113.10"],
  "dnsMX": ["mail.example.com"],
  "dnsNS": ["ns1.somehost.com"],
  "scannedAt": "2026-06-29T00:00:00+00:00"
}
```

### Data fields

| Field | Description |
|---|---|
| `variantDomain` | The look-alike domain found |
| `fuzzer` | Permutation technique (omission, homoglyph, tld-swap, addition, ...) |
| `registered` | Whether the domain resolves (has DNS records) |
| `hasMailServer` | Whether it has an MX record (can send/receive email → phishing risk) |
| `dnsA` / `dnsAAAA` | IPv4 / IPv6 addresses |
| `dnsMX` / `dnsNS` | Mail servers / nameservers |

### Pricing / Cost estimation

This Actor is **pay-per-result**: you are charged **$0.03 per registered look-alike domain** discovered. A typical brand has a handful to a few dozen registered look-alikes, so most scans cost a few cents to under a dollar. Invalid input and "no look-alikes found" runs are **free**. New Apify users get free monthly credits to start.

### Tips & advanced options

- Keep `registeredOnly: true` for signal over noise — unregistered permutations are not an active threat.
- Watch the `hasMailServer` flag: a look-alike with MX records is set up to send email and is a high-priority phishing risk.
- Schedule a weekly run and diff the results to catch **newly registered** copycats early.

### FAQ, disclaimers & support

**Is this legal?** Yes — it only generates name permutations and queries **public DNS**, the same data any DNS resolver returns. It does not access private data or the target domains' content. Use it for defensive brand protection and authorized research.

**Known limitations:** DNS results depend on resolver propagation; very large brands may exceed the result cap (raise `maxResults`). Homoglyph detection follows dnstwist's database.

- Found a bug or need a custom OSINT/brand-protection solution? Open an issue in the **Issues** tab.

***

### 🔗 Related Actors by ntriqpro

Build your full OSINT & brand-protection stack:

- [**maigret-actor**](https://apify.com/ntriqpro/maigret-actor) — Username OSINT across 3000+ sites
- [**email-osint-search**](https://apify.com/ntriqpro/email-osint-search) — Find which 120+ sites an email is registered on
- [**theharvester-osint**](https://apify.com/ntriqpro/theharvester-osint) — Subdomains, hosts & emails for a domain
- [**whois-domain-lookup**](https://apify.com/ntriqpro/whois-domain-lookup) — WHOIS registration intelligence

### ⭐ Love it? Leave a Review

Your rating helps other defenders discover this Actor. [Rate it here](https://apify.com/ntriqpro/dnstwist-osint/reviews).

# Actor input Schema

## `domain` (type: `string`):

The domain to protect, e.g. "example.com" (no http://, no path). The Actor generates thousands of permutations and checks which are registered.

## `registeredOnly` (type: `boolean`):

Only return permutations that are actually registered (have DNS records) — the real threats. Turn off to also list unregistered permutations.

## `maxResults` (type: `integer`):

Maximum look-alike domains to return and charge for (hard cap 500).

## `timeout` (type: `integer`):

Maximum time for the DNS permutation scan.

## Actor input object example

```json
{
  "domain": "example.com",
  "registeredOnly": true,
  "maxResults": 200,
  "timeout": 300
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domain": "example.com",
    "maxResults": 200,
    "timeout": 300
};

// Run the Actor and wait for it to finish
const run = await client.actor("ntriqpro/dnstwist-osint").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "domain": "example.com",
    "maxResults": 200,
    "timeout": 300,
}

# Run the Actor and wait for it to finish
run = client.actor("ntriqpro/dnstwist-osint").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domain": "example.com",
  "maxResults": 200,
  "timeout": 300
}' |
apify call ntriqpro/dnstwist-osint --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=ntriqpro/dnstwist-osint",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/Dr0bmuiZjpn9Nkyzh/builds/EIjUt4EVlDmg6j3Ig/openapi.json
