Three lookalikes were mentioned in the brief. The exposure is what they are doing, what else exists that nobody mentioned, and what that costs — all of it from public data.
The three named
| Domain | Observed | Classification |
|---|---|---|
calder-voss.com | Registered 11 days ago. Resolves. Certificate issued 2 days ago. MX present. Serves a login page matching the customer portal, favicon byte-identical. | Live phishing. Operational. |
calderandvoss.net | Registered 63 days ago. Resolves to a parking page with advertising. No MX, no certificate. | Parked or monetised. Log it. |
caldervoss.com | Registered 88 days ago. No records at all beyond nameservers. | Unknown. Watchlist. Promote on any change. |
What else exists
Search CT for the brand string, not just the three: crt.sh ?q=%25calder%25 -> two more names calderandvoss-support.example cert 5 days ago secure-calderandvoss.example cert 5 days ago Same issuance day. Resolve both: same two nameservers as calder-voss.com Five domains, one campaign. The brief named three.
The clustering is the finding. Three separate registrations is a nuisance; five sharing nameservers and a certificate window is an operator running a campaign against this company, and that is a different conversation with a different urgency.
Quantifying it honestly
| Can state | Cannot state |
|---|---|
| Five domains, clustered by shared nameservers and issuance timing | Who registered them |
| One is serving a credential-harvesting page as of a captured time | How many customers have visited it |
| Two are prepared to receive mail as the brand | Whether any mail has been received |
All of this happened while the primary is at p=none | That the two facts are causally connected |
| The campaign began within the last 90 days | That it is the first one |
The right-hand column matters as much as the left. A report claiming customer losses it cannot evidence is a report whose other claims get discounted.
Capture before writing any of this down
The live one is serving content now and will not be tomorrow. Screenshot, raw HTML, headers, DNS, certificate and RDAP — for all five, at the moment of discovery, with a manifest. Everything in this lesson is unrecoverable once a host acts.