Domain Guardian: explanation
Domain Guardian is the latest feature to LetsDMARC. It consist in an additional service that checks daily all the newly registered domains, cross checking them with the domains currently configured in your LetsDMARC environment. The objective is to identify immediately domains created with the sole purpose of impersonate a company or its branding and conduct massive phishing campaigns.
Differently from traditional systems of similarity recognition that rely only on matching string of text, homoglyph or transliteration, Domain Guardian uses the proprietary algorithm NeuroPhish.
This algorithm uses an artificial intelligence model trained to replicate the human perceptions: it doesn't only match the texts, but it evaluates the visible and perceptible similarity between the domains managed and the ones just created, just as human check would do.
The algorithm NeuroPhish run its calculation on a private GPU cluster which is property of the LibraCyber infrastructure, guaranteeing privacy first and top of the line analysis.
This allow to spots threats immediately, alert the client and make an intervention before any damage to the branding or the company can be caused.
Domain Guardian: how to use it
The feature is not available to every customer, since it needs to be purchased additionally.
If you see this prompt, please contact your sales representative to obtain the upgraded license.
After obtaining the correct license, you will be shown the list of the domains currently managed inside LetsDMARC.
In this list, for each domain selected, it possible to see quickly how many similar domain were spotted by the NeuroPhish algorithm in the Last Day, Last 7 Days, Last 28 Days.
By selecting a specific domain, we can see:
- The similar domain spotted by the NeuroPhish algorithm
- The date of the first time the new similar domain has been spotted
- Additional DNS record discovered for this domain (record A, AAAA, MX, TXT, CNAME, NS)
- Level of similarity
You can also filter alphabetically by domain, by most recent date or highest / lowest similarity level.
Domain Guardian: Actions
Set as Verified (Checkmark Icon) / Set as to Review (Eye Icon):
The action "Set as Verified (Checkmark Icon)" will hide the domain selected, this is useful when the spotted domain has been registered by the customer and not by another entity trying to impersonate.
Once hidden, they will disappear from the "Not Verified" view but can be still shown by clicking the button “Show All” in the right upper corner.
The action "Set as to Review (Eye Icon)" will put back the domain in the "Not Verified" view and will be shown as possible impersonation.
Report Abuse (Email Icon):
The action "Report Abuse (Email Icon)" will create a prompt email to be send to the registrar of the newly spotted domain and report the abuse together with asking the takedown of the domain.
The product LetsDMARC doesn't guarantee the effectiveness of the takedown action since the final decision will always be upon the domain registrar.
Additional DNS records discovery
For each similar domain detected by Domain Guardian, LetsDMARC also performs a DNS records discovery to provide more technical context about the domain. The platform checks DNS records such as A, AAAA, MX, TXT, CNAME, and NS are present, helping administrators understand if the domain is actively used.
A green check indicates that the record exists, while a gray cross means that no record was found.
By moving the mouse over a green check, it is possible to view the actual DNS values detected for that record type.
Domain Guardian: how to set up alert
To setup an alert every time the Domain Guardian spot another similar domain you can follow this guide, and select "Domain Guardian Event" as the "Alert Type" in the Alert Settings.