SOUNDTRACK // IRON UNDER PRESSURE
JEZWEB // GRID OSv2026
JEZWEB

> product // domain dingo // live

Domain Dingo
watching your name.

Scammers register lookalikes of Australian business domains and use them to invoice your customers. Domain Dingo watches for those registrations, finds the ones impersonating you, and gets them blocked.

free scan, no signup ↗monitoring included with every packhas its own MCP serverdomaindingo.au ↗

The classic invoice scam starts with a domain: your business name with one letter changed, or the same name on a different ending. Email gets set up on it, your customers get a convincing invoice with new bank details, and you find out when the money is already gone. Nobody was watching for that registration, and that is the whole trick.

What it does

Finds the lookalikes

Watches new registrations for domains built to be mistaken for yours.

Gets them blocked

Acts on what it finds rather than just listing it in a report.

Keeps watching

Ongoing monitoring, because a name is worth impersonating for as long as it is worth trading under.

  • You hear about a lookalike before your customers hear from it
  • The obvious variants sit registered in your name instead of waiting for someone worse
  • Something is checking every day, instead of you finding out from an angry supplier
  1. 01Start with a free scan: no signup, just your domain
  2. 02It generates the lookalikes a scammer would pick: misspellings, swapped endings, added words
  3. 03A daily watch checks new registrations against your business name, not just one domain
  4. 04Threats get scored: a lookalike that starts sending email is flagged as invoice-fraud preparation
  5. 05You get an alert with the practical next steps, including locking the variants away yourself

Built for Australian businesses that invoice by email: trades, construction, professional services, real estate — anywhere a changed bank detail on a PDF costs real money.

Not for you if you have an enterprise brand-protection team and takedown lawyers on retainer. This is that protection at a size an SME can actually run.

DetectionAI variant generation plus BEC-focused algorithms: combosquatting, TLD swaps, homoglyphs
Threat signalDNS checks on every discovered domain; a new mail record scores highest
Name watchABR monitoring for confusably similar business-name registrations
PlatformCloudflare Workers, D1, Queues, a daily cron
InterfacesWeb dashboard, the dingo CLI, and its own MCP server

I already own my domain. Am I not covered?

Owning yours does not stop anyone registering a near-miss of it. The scam runs on a domain you never owned, so protection means watching variants of your name across endings, not holding one domain.

How do you know a lookalike is actually dangerous?

DNS gives it away. A freshly registered lookalike that sets up email is preparing to send something, usually an invoice. Those score highest and trigger the alert.

What happens when it finds one?

You get an alert naming the domain and what it is doing, sending email or standing up a website, plus the still-available variants worth registering defensively before anyone else does.

Do I have to move my domain or hosting to you?

No. The watch reads public registration and DNS records from the outside. Nothing about your existing setup changes.

Want Domain Dingo for your business?

Tell us what you need. We’ll give you a straight answer on whether it fits.