A domain monitoring programme finds domains. Most brand impersonation does not involve one, which is a limitation worth stating clearly rather than discovering during an incident review.
What never appears
| Technique | Why monitoring misses it |
|---|---|
| Display-name spoofing | A free mail account with your brand as the display name. No domain, no registration, nothing to detect. |
| Subdomain-shaped deception | The brand is a subdomain label on the attacker’s own domain. Created for free, unlimited variants. |
| Compromised legitimate sites | The phishing page is hosted on a real business’s real domain that was broken into. |
| Social platform impersonation | A profile, not a domain. Entirely outside DNS. |
| Messaging and SMS | Sender IDs and phone numbers. No domain involved at all. |
| Compromised supplier mailboxes | Genuine domain, genuine mail, genuine authentication. Nothing is impersonated. |
| QR codes in printed material | Nothing observable online until somebody scans one. |
Why it matters to say so
- Coverage claims get tested by incidents. A programme described as catching brand impersonation will be judged against the first one it could never have seen.
- Budget follows stated scope. Overstating what monitoring covers means the controls that address the rest — user-facing warnings, payment verification, supplier processes — never get funded.
- Analysts stop trusting their own tooling when it is presented as complete and is visibly not.
What it does cover, properly stated
Registered lookalike domains, found within hours of a certificate being issued or an MX appearing, triaged into four categories, with evidence assembled for the ones that warrant it. That is a real and worthwhile capability. It is also one technique out of seven, and the other six belong to other controls and other owners.
The honest one-line description
“We detect lookalike domain registrations targeting the brand, usually within hours of them becoming usable.” Not “we monitor for brand impersonation”, which claims the other six.