Fake domains blocked before your users ever reach them

Fake domains blocked before your users ever reach them

We find the phishing and typosquatting domains impersonating your brand the moment they go live, block them at the point of access, and take them down at the source.

Protect your brand and community in real time with AI + human experts.

Protect your brand and community in real time with AI + human experts.

Officialacme.com
Fakeacme-secure.com
Fakeacmee.com
Fakeacm3.com
28+ sources scanning 24/7
acme-secure.com
This site has been blockedSite blocked · flagged as phishing
Takedown request
acme-secure.com
Provider identified
Evidence attached
TODO
IN PROGRESS
COMPLETED
Threat removed · confirmed offline

Why blocking first beats takedowns alone

A takedown can take days. A user can lose funds in minutes. That’s why we block first and take down second.

Detect fakes the moment they’re registered

Our detection sources monitor Certificate Transparency logs, DNS records, and search indexes around the clock. A new domain that looks, sounds, or resolves like yours gets flagged before it ever reaches a user’s feed.

Block at the point of access

The moment a domain is confirmed malicious, it goes on our blocklist. That blocklist reaches wallets, browsers, and security partners within minutes, so users get warned before they connect a wallet or enter a seed phrase.

Take it down at the source

While the blocklist is protecting users, we file the takedown with the hosting provider or registrar. The site comes offline, and we keep monitoring in case it reappears under a new domain.

Wherever scammers register domains, we’re already watching

Typosquatters don’t wait for a launch to register lookalike domains. Neither do we.

Typosquatting

Lookalike domains built from homoglyphs and common misspellings, like chainpatr0l.com or chianpatrol.com, caught the moment they’re registered.

Fake airdrop pages and wallet drainers

Cloned landing pages timed to launches and mints, and domains running malicious smart contracts that drain a connected wallet the moment a user signs.

Cloned brand sites

Full copies of your official site, sometimes down to the last pixel, built to harvest credentials or seed phrases.

Parked and dormant domains

Lookalike domains registered early and held until a scam campaign is ready to go live.

These are a few of the patterns we cover, not the full list. Detection runs across 28+ sources, including Certificate Transparency monitoring, typosquatting analysis, and third-party threat intel.

Why the best brands don’t handle domain takedowns alone

Most brands either wait for users to report fake domains or use a tool that flags them and hands the problem back. We flag them, block them, and take them down, without your team touching it.

Other Tools
Dedicated staff included
Rare
Time to block a domain
Not offered
Detection method
Automated only
DNS / registrar coverage
Limited
Time to full takedown
Days to weeks, no visibility
ChainPatrol
24/7 team included
Minutes via wallets/DNS, 1–2 hrs via Safe Browsing
Human plus AI
28+ sources, direct registrar & TLD contacts
Hours to days, fully tracked
Other Tools
  • Dedicated staff included: Rare
  • Time to block a domain: Not offered
  • Detection method: Automated only
  • DNS / registrar coverage: Limited
  • Time to full takedown: Days to weeks, no visibility
ChainPatrol
  • Dedicated staff included: 24/7 team included
  • Time to block a domain: Minutes via wallets/DNS, 1–2 hrs via Safe Browsing
  • Detection method: Human plus AI
  • DNS / registrar coverage: 28+ sources, direct registrar & TLD contacts
  • Time to full takedown: Hours to days, fully tracked

Trusted by 100+ brands to protect their users from fake domains

The most targeted names rely on us to keep phishing domains away from their communities.

“Keeping the Arbitrum community safe is an iterative and ongoing process that ChainPatrol has helped to simplify, as well as improve, with the removal of over 4000+ threats and scams.”

Arbitrum Foundation

@Eli_DeFi, Community Lead

“ChainPatrol stood out with their impressive reporting capabilities, an active and involved team, and superior wallet blocking integration.”

Consensys

Luker

FAQ

Frequently asked questions

How ChainPatrol finds fake domains, blocks them in minutes, and takes them down at the source.

General

Any domain that impersonates your brand. That means typosquatted URLs, lookalike domains using homoglyphs or common misspellings, cloned sites under misleading names, and parked domains registered to ride a future campaign. If it's designed to make users think they've landed on your site, it counts.

Domain protection stops fake websites. Social account protection stops fake profiles. They're different threats on different infrastructure, and both require separate monitoring. This page covers the domain side, the phishing and typosquatting sites impersonating you across the web.

Detection

We monitor Certificate Transparency logs, DNS registration feeds, search indexes, and third-party threat intelligence sources around the clock. New domains that look, sound, or resolve like yours get flagged immediately, before a single user sees them.

Typosquatting is about the domain itself, a lookalike URL designed to catch users who mistype your address. A cloned phishing page is about the content, a fabricated site designed to trick users into entering credentials or taking a harmful action. Both are threats we detect and remove.

Every flagged domain is reviewed by our team before action is taken. We check registration history, DNS records, site content, and behavioral signals. Human plus AI validation keeps our false-positive rate low so legitimate sites are never accidentally blocked or taken down.

Blocking & Takedowns

Within minutes of confirmation. Once a domain is verified as malicious, it goes on our blocklist and pushes immediately to wallets, browsers, and DNS security partners. Users are warned before they can enter credentials or take any action on the site.

Our blocklist feeds into browser security extensions, DNS-level security partners, and crypto wallets. The exact list of partners grows over time, but coverage is designed to intercept users at every common point of access before they reach the malicious site.

Typically hours for hosting-level takedowns, and one to three days for registrar or DNS-level removals. We file with the hosting provider or registrar directly and track every submission through to completion. Your team doesn't have to follow up.

No. This is fully managed. We detect, verify, block, and file on your behalf, and you can see the full activity in your dashboard. Your team only needs to get involved if you want to.

Coverage

We keep monitoring. If the same campaign relaunches under a new domain, our detection systems flag it automatically. Serial offenders get escalated through our abuse network contacts so the pattern gets broken, not just the individual site.

We escalate. If a standard abuse report doesn't get actioned, we route through secondary contacts, upstream network providers, or alternate legal channels. The blocklist stays active the whole time so users remain protected even while the formal process plays out.

Still have questions? Book a demo and ask us directly.

See the fake domains targeting your brand right now

We’ll scan the web and show you exactly which domains are impersonating you. Results in 48 hours. No credit card required.