Blog
Field notes on
clones & cloaking
How phishing impersonation actually works — cloaking tricks, lookalike-domain signals, the takedown process and the practices that keep a brand safe.
How to report a phishing site and actually get it removed
Where to send a phishing report, what each abuse desk needs to see, and the evidence that turns a report into a removal instead of a dead-end ticket.
Read article Cloaking · 9 minMobile cloaking explained: one URL, two realities
How phishing pages show search crawlers a clean site and real mobile visitors a credential trap — and how dual-profile crawling proves the redirect.
Read article Detection · 7 minTyposquatting vs. homoglyph attacks, explained
Two ways attackers fake your domain — one exploits typing mistakes, the other uses look-alike characters. How each works and how to catch both early.
Read article Takedowns · 8 minThe phishing takedown process: abuse channels, step by step
Registrars, hosts, CDNs and safe-browsing desks — where to file, what evidence each one wants, and why routing beats blasting.
Read article Threats · 8 minWhat is credential harvesting? How phishing steals logins
Credential harvesting is the engine behind most phishing. How fake login pages capture passwords, where the data goes, and how to shut the pipeline down.
Read article Detection · 7 minHow to detect lookalike domains before they go live
Typosquatting, homoglyphs and combosquatting — the signals that expose impersonation domains early, from registration to first crawl.
Read article Threats · 7 minFake login pages: how to spot one before you type
Cloned sign-in screens are the sharp end of phishing. The tells that give them away, and why your customers need you watching rather than relying on their eyes.
Read article Best practices · 10 minBrand protection best practices: a checklist for 2026
A practical playbook for protecting your brand from phishing impersonation — monitoring, evidence, takedowns and the metrics that matter.
Read article Threats · 8 minBrand impersonation on social media: a response playbook
Fake profiles, cloned pages and lookalike handles target your customers off your own site. How to find, evidence and take down social impersonation.
Read article Evidence · 7 minWhy a screenshot isn't enough evidence for a takedown
A screenshot is easy to dismiss and easy to fake. What abuse desks actually need — headers, the cloaking diff and timestamps — to act on first submission.
Read article Detection · 8 minCertificate Transparency for brand monitoring
Every TLS certificate is logged publicly. How to turn Certificate Transparency logs into an early-warning system for clones and lookalike domains.
Read article Threats · 9 minPhishing-as-a-Service (PhaaS), explained
Phishing is now a subscription product: kits, cloaking and hosting sold ready-made. What PhaaS is, why it scales attacks, and what actually stops it.
Read article Threats · 7 minSmishing: how SMS phishing works and how to fight it
Phishing by text message bets on urgency and small screens. How smishing lures work, why links are so dangerous on mobile, and how to shut down the pages behind them.
Read article Threats · 7 minVishing: voice phishing and callback scams explained
Phone-based phishing uses a human voice to bypass caution. How vishing and callback scams work, the role of spoofed numbers, and where brand protection fits in.
Read article Email security · 9 minBusiness Email Compromise (BEC), explained
BEC skips malware and targets trust: fake invoices, wire fraud and impersonated executives. How it works, why it is so costly, and how to defend against it.
Read article Threats · 7 minSpear phishing vs. mass phishing: what's the difference?
One is a net, the other a spear. How targeted spear phishing differs from mass campaigns, why it works, and what defences actually apply to each.
Read article Threats · 6 minWhaling: phishing that targets the executives
Whaling aims at leadership, where one approval moves money. How executive-targeted phishing works and the controls that stop a convincing impersonation.
Read article Threats · 6 minClone phishing: when a real email comes back poisoned
Clone phishing copies a legitimate message and swaps the link or attachment. Why the familiarity makes it dangerous and how to recognise and stop it.
Read article Threats · 6 minQR code phishing (quishing): the scan-and-steal scam
A QR code hides its destination until you scan it. How quishing abuses that trust, where fake codes appear, and how to defend your brand and customers.
Read article Threats · 7 minPharming: when the right address sends you to a fake site
Pharming poisons the path between a correct address and the real server. How DNS-based redirection works, why it is hard to spot, and how to reduce the risk.
Read article Threats · 7 minMalvertising: fake ads that impersonate your brand
Attackers buy ads on your own brand terms to outrank you and send customers to clones. How malvertising works and how to detect and take it down.
Read article Email security · 7 minHow to spot a phishing email: the red flags that matter
The reliable signals of a phishing email — and the ones that no longer hold. A practical guide for people, plus why brands can't rely on it alone.
Read article Email security · 9 minDMARC, SPF and DKIM: stop attackers spoofing your domain
Three email-authentication standards decide whether someone can send mail as you. What SPF, DKIM and DMARC do, and how to roll them out without breaking mail.
Read article Email security · 6 minEmail spoofing: how attackers fake your 'from' address
Why email lets anyone forge a sender, how spoofing underpins phishing and BEC, and the authentication that makes your domain hard to impersonate.
Read article Detection · 8 minDomain monitoring: a practical buyer's guide
What domain monitoring should actually do, the signals that matter, and the questions to ask — so you catch lookalikes early instead of paying for noise.
Read article Best practices · 7 minBrandjacking: when someone hijacks your identity online
Brandjacking covers domains, social handles, ads and apps that seize your identity. The forms it takes and how to reclaim and defend your brand.
Read article Defense · 6 minDoes the padlock mean a site is safe? The HTTPS myth
The padlock means encrypted, not trustworthy. Why most phishing sites now use HTTPS, and what actually tells you whether a login page is real.
Read article Threats · 8 minAccount takeover (ATO): how one phish becomes many
Account takeover is where phishing pays off. How stolen credentials turn into fraud, why reuse spreads the damage, and how to break the chain.
Read article Threats · 7 minCredential stuffing vs. brute force: know the difference
Both attack logins, but in opposite ways. How credential stuffing reuses stolen passwords at scale, how brute force differs, and what stops each.
Read article Detection · 7 minDark web monitoring for leaked credentials
Leaked passwords fuel account takeover. What dark web monitoring can and can't do, how to act on a hit, and where it fits in a brand-protection programme.
Read article Defense · 9 minPhishing incident response: what to do when customers are hit
A clear, calm playbook for the first hours of a phishing attack on your brand — contain, evidence, take down, communicate and learn.
Read article Threats · 8 minAI-powered phishing and deepfakes: the new frontier
AI writes flawless lures and clones voices and faces. How attackers use it, why old 'spot the typo' advice is failing, and what still works.
Read articleStop reading about clones — remove yours
Run a free clone check on one domain and see detection, cloaking forensics and evidence in one pass.