SOCIAL MEDIA

Detect typosquatted brand domains and block them at Cloudflare with a Slack approval

Generates and checks likely typosquat variations of your domain, flags newly registered or live lookalikes hosting fake login or social pages.

CategorySocial Media
Enginesim
Difficultyadvanced
Triggerschedule
Steps7
Setup~25 min

How it runs

The automated pipeline, trigger to output.

  • TriggerDaily schedule
  • ActionGenerate and resolve typosquat domain variantsShell
  • ActionLoad live lookalikes and capture contentBrowserbase
  • ActionJudge brand/login impersonation and severityOpenAI
  • LogicRoute high-severity hits, drop parked pages
  • ActionPost Slack approval card with evidenceSlack
  • OutputBlock approved domain in Cloudflare GatewayCloudflareCloudflare

What it does

It hunts for lookalike domains that imitate your brand to phish your customers, confirms which ones are actually live, and turns each confirmed threat into a one-click Cloudflare block gated by human approval.

When to use it

Use this when scammers register near-miss domains (swapped letters, added hyphens, alternate TLDs) to host fake login or social-redirect pages. It suits security and brand teams who want fast blocking without auto-acting on false positives.

How it works

  1. 1A daily schedule starts the run.
  2. 2A shell step generates typosquat permutations and resolves which are registered and responding.
  3. 3Browserbase loads each live candidate and grabs its content and a screenshot.
  4. 4OpenAI judges whether the page impersonates your brand or login flow and assigns severity.
  5. 5A logic branch routes high-severity hits onward and drops benign parked pages.
  6. 6Slack posts an approval card with the evidence; on approval, Cloudflare Gateway adds the domain to a block policy.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect ShellRun sandboxed commands inside the workspace.
  2. 2
    Connect BrowserbaseHeadless browsers, sessions, replays.
  3. 3
    Connect OpenAIModels, embeddings, files.
  4. 4
    Connect SlackChannels, DMs, threads, mentions.
  5. 5
    Connect CloudflareWorkers, Pages, R2, KV — the edge stack.
  6. 6
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  7. 7
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  8. 8
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.