Spot the impostors.

Type a website to see what it exposes and who is pretending to be it. Type a username to find everywhere it lives.

Try , or

How Sleuth works

It only reads what's already public. Nothing is attacked, logged into or probed beyond loading a homepage, like any visitor would.

  1. Exposure. DNS and email records, registration data, certificate logs for subdomains, Shodan's open-port index, server locations, security headers and the Wayback Machine.
  2. Lookalike domains. Hundreds of typo, swapped-letter, foreign-alphabet and “-login” variants are generated and checked. Registered ones are profiled: can they receive mail, how new are they, do they show a login page?
  3. Accounts. The handle is checked on 200+ sites using the open-source Sherlock project's rules, plus support-style variants on scam-prone platforms.

Use it on organisations you work for or study, and on your own usernames. Results are kept for six hours, so repeat scans replay instantly.