CertaDNS
Skip to lesson

What Detection Misses · lesson 1 of 2

What monitoring cannot see

After this lesson you can

Name the impersonation techniques no domain monitoring will ever surface.

Assumes you have read The cost of being wrong.

A domain monitoring programme finds domains. Most brand impersonation does not involve one, which is a limitation worth stating clearly rather than discovering during an incident review.

What never appears

TechniqueWhy monitoring misses it
Display-name spoofingA free mail account with your brand as the display name. No domain, no registration, nothing to detect.
Subdomain-shaped deceptionThe brand is a subdomain label on the attacker’s own domain. Created for free, unlimited variants.
Compromised legitimate sitesThe phishing page is hosted on a real business’s real domain that was broken into.
Social platform impersonationA profile, not a domain. Entirely outside DNS.
Messaging and SMSSender IDs and phone numbers. No domain involved at all.
Compromised supplier mailboxesGenuine domain, genuine mail, genuine authentication. Nothing is impersonated.
QR codes in printed materialNothing observable online until somebody scans one.

Why it matters to say so

  • Coverage claims get tested by incidents. A programme described as catching brand impersonation will be judged against the first one it could never have seen.
  • Budget follows stated scope. Overstating what monitoring covers means the controls that address the rest — user-facing warnings, payment verification, supplier processes — never get funded.
  • Analysts stop trusting their own tooling when it is presented as complete and is visibly not.

What it does cover, properly stated

Registered lookalike domains, found within hours of a certificate being issued or an MX appearing, triaged into four categories, with evidence assembled for the ones that warrant it. That is a real and worthwhile capability. It is also one technique out of seven, and the other six belong to other controls and other owners.

The honest one-line description

“We detect lookalike domain registrations targeting the brand, usually within hours of them becoming usable.” Not “we monitor for brand impersonation”, which claims the other six.

Last reviewed