Blog

Field notes on
clones & cloaking

How phishing impersonation actually works — cloaking tricks, lookalike-domain signals, the takedown process and the practices that keep a brand safe.

Takedowns · 8 min

How to report a phishing site and actually get it removed

Where to send a phishing report, what each abuse desk needs to see, and the evidence that turns a report into a removal instead of a dead-end ticket.

Read article
Cloaking · 9 min

Mobile cloaking explained: one URL, two realities

How phishing pages show search crawlers a clean site and real mobile visitors a credential trap — and how dual-profile crawling proves the redirect.

Read article
Detection · 7 min

Typosquatting vs. homoglyph attacks, explained

Two ways attackers fake your domain — one exploits typing mistakes, the other uses look-alike characters. How each works and how to catch both early.

Read article
Takedowns · 8 min

The phishing takedown process: abuse channels, step by step

Registrars, hosts, CDNs and safe-browsing desks — where to file, what evidence each one wants, and why routing beats blasting.

Read article
Threats · 8 min

What is credential harvesting? How phishing steals logins

Credential harvesting is the engine behind most phishing. How fake login pages capture passwords, where the data goes, and how to shut the pipeline down.

Read article
Detection · 7 min

How to detect lookalike domains before they go live

Typosquatting, homoglyphs and combosquatting — the signals that expose impersonation domains early, from registration to first crawl.

Read article
Threats · 7 min

Fake login pages: how to spot one before you type

Cloned sign-in screens are the sharp end of phishing. The tells that give them away, and why your customers need you watching rather than relying on their eyes.

Read article
Best practices · 10 min

Brand protection best practices: a checklist for 2026

A practical playbook for protecting your brand from phishing impersonation — monitoring, evidence, takedowns and the metrics that matter.

Read article
Threats · 8 min

Brand impersonation on social media: a response playbook

Fake profiles, cloned pages and lookalike handles target your customers off your own site. How to find, evidence and take down social impersonation.

Read article
Evidence · 7 min

Why a screenshot isn't enough evidence for a takedown

A screenshot is easy to dismiss and easy to fake. What abuse desks actually need — headers, the cloaking diff and timestamps — to act on first submission.

Read article
Detection · 8 min

Certificate Transparency for brand monitoring

Every TLS certificate is logged publicly. How to turn Certificate Transparency logs into an early-warning system for clones and lookalike domains.

Read article
Threats · 9 min

Phishing-as-a-Service (PhaaS), explained

Phishing is now a subscription product: kits, cloaking and hosting sold ready-made. What PhaaS is, why it scales attacks, and what actually stops it.

Read article
Threats · 7 min

Smishing: how SMS phishing works and how to fight it

Phishing by text message bets on urgency and small screens. How smishing lures work, why links are so dangerous on mobile, and how to shut down the pages behind them.

Read article
Threats · 7 min

Vishing: voice phishing and callback scams explained

Phone-based phishing uses a human voice to bypass caution. How vishing and callback scams work, the role of spoofed numbers, and where brand protection fits in.

Read article
Email security · 9 min

Business Email Compromise (BEC), explained

BEC skips malware and targets trust: fake invoices, wire fraud and impersonated executives. How it works, why it is so costly, and how to defend against it.

Read article
Threats · 7 min

Spear phishing vs. mass phishing: what's the difference?

One is a net, the other a spear. How targeted spear phishing differs from mass campaigns, why it works, and what defences actually apply to each.

Read article
Threats · 6 min

Whaling: phishing that targets the executives

Whaling aims at leadership, where one approval moves money. How executive-targeted phishing works and the controls that stop a convincing impersonation.

Read article
Threats · 6 min

Clone phishing: when a real email comes back poisoned

Clone phishing copies a legitimate message and swaps the link or attachment. Why the familiarity makes it dangerous and how to recognise and stop it.

Read article
Threats · 6 min

QR code phishing (quishing): the scan-and-steal scam

A QR code hides its destination until you scan it. How quishing abuses that trust, where fake codes appear, and how to defend your brand and customers.

Read article
Threats · 7 min

Pharming: when the right address sends you to a fake site

Pharming poisons the path between a correct address and the real server. How DNS-based redirection works, why it is hard to spot, and how to reduce the risk.

Read article
Threats · 7 min

Malvertising: fake ads that impersonate your brand

Attackers buy ads on your own brand terms to outrank you and send customers to clones. How malvertising works and how to detect and take it down.

Read article
Email security · 7 min

How to spot a phishing email: the red flags that matter

The reliable signals of a phishing email — and the ones that no longer hold. A practical guide for people, plus why brands can't rely on it alone.

Read article
Email security · 9 min

DMARC, SPF and DKIM: stop attackers spoofing your domain

Three email-authentication standards decide whether someone can send mail as you. What SPF, DKIM and DMARC do, and how to roll them out without breaking mail.

Read article
Email security · 6 min

Email spoofing: how attackers fake your 'from' address

Why email lets anyone forge a sender, how spoofing underpins phishing and BEC, and the authentication that makes your domain hard to impersonate.

Read article
Detection · 8 min

Domain monitoring: a practical buyer's guide

What domain monitoring should actually do, the signals that matter, and the questions to ask — so you catch lookalikes early instead of paying for noise.

Read article
Best practices · 7 min

Brandjacking: when someone hijacks your identity online

Brandjacking covers domains, social handles, ads and apps that seize your identity. The forms it takes and how to reclaim and defend your brand.

Read article
Defense · 6 min

Does the padlock mean a site is safe? The HTTPS myth

The padlock means encrypted, not trustworthy. Why most phishing sites now use HTTPS, and what actually tells you whether a login page is real.

Read article
Threats · 8 min

Account takeover (ATO): how one phish becomes many

Account takeover is where phishing pays off. How stolen credentials turn into fraud, why reuse spreads the damage, and how to break the chain.

Read article
Threats · 7 min

Credential stuffing vs. brute force: know the difference

Both attack logins, but in opposite ways. How credential stuffing reuses stolen passwords at scale, how brute force differs, and what stops each.

Read article
Detection · 7 min

Dark web monitoring for leaked credentials

Leaked passwords fuel account takeover. What dark web monitoring can and can't do, how to act on a hit, and where it fits in a brand-protection programme.

Read article
Defense · 9 min

Phishing incident response: what to do when customers are hit

A clear, calm playbook for the first hours of a phishing attack on your brand — contain, evidence, take down, communicate and learn.

Read article
Threats · 8 min

AI-powered phishing and deepfakes: the new frontier

AI writes flawless lures and clones voices and faces. How attackers use it, why old 'spot the typo' advice is failing, and what still works.

Read article

Stop reading about clones — remove yours

Run a free clone check on one domain and see detection, cloaking forensics and evidence in one pass.