Reference

Domain enforcement reference

Two things decide whether an impersonating domain comes down: knowing which party in the chain can actually switch it off, and being able to read the registration record afterwards to see who did. Neither is written down anywhere useful, so this is our working reference, published.

It is free and it is not a lead magnet — there is no form on these pages. We publish it because the reading is the part of this work that is genuinely hard to get right, and a wrong reading gets a real business suspended.

Domain status codes

A page going dark is not a result. serverHold is the registry and is effectively final; clientHold is the registrar and can be lifted by the same registrar; clientTransferProhibited is usually a default setting and means nobody did anything at all. 23 codes, each with who set it and what it tells you.

Top-level domains

Who operates the registry, and where the registration record lives. 49 TLDs, included because they are a Southeast Asian ccTLD, a commerce-intent gTLD, a name clones commonly sit on, or one we have measured impersonating domains on.

Across 30 brand sweeps, 103 live lookalikes resolved. The TLDs they sat on, most to least: .com (50), .shop (16), .net (10), .co (6), .online (6). A count of what resolved, not of confirmed impersonation.

Commerce gTLDs

What a fake outlet is buying.

The common names

Where clones are registered most often.

Southeast Asian ccTLDs

The jurisdiction this practice works in.

Sources: IANA RDAP bootstrap · ICANN EPP status codes · Last built 2026-09-20