Automatically detect newly registered domains that mimic your brand or customers and flag likely phishing, typosquatting, and abuse targets for early investigation. Get ahead of attackers before they deploy infrastructure. Start with our free domain blacklist checker to see if a domain is already flagged.
Attackers don't email first — they register paypa1.com, microsft-login.io, or yourbrand-support.net and wait. By the time a phishing email reaches an inbox, the domain has aged past new-domain blocks. Primitive Host flips the timeline. We scan 276M+ domains daily for brand keywords, homoglyphs, and typosquat patterns across every TLD, then flag high-risk registrations within hours. Your brand protection and SOC teams get a prioritized feed before the domain ever serves a payload, with DNS and WHOIS context to decide block, takedown, or watch. Built for teams who can't afford to discover abuse from a customer complaint.
What you can do
Catch Phishing Before the Email
Block lookalikes hours after registration — before they are weaponized for campaigns.
Typosquat Inventory & Prioritization
Map every variant of your brand across TLDs and rank by DNS, age and hosting risk signals.
Automate SOAR Triage
Push verified alerts to Sentinel, Splunk, Jira or Slack with context for block or takedown workflows.
Key features
- Brand keyword and homoglyph pattern matching across 5,625+ TLDs
- Typosquatting and lookalike detection with risk scoring
- Domain blacklist checker with 12 real-time DNSBLs
- Real-time alerts on suspicious new registrations via webhook & feed
- Feed integrations for SIEM, SOAR, Jira, Slack and ticketing platforms
- Historical archive for retrospective abuse analysis
GET /v1/domains?contains=acme®istered_since=2025-09-01&risk=high
Authorization: Bearer <token>
{
"domains": [{"domain": "acme-secure-login.com", "risk": "high", "reason": "homoglyph + new"}],
"alerts": 12
}