Domain Monitor Now Catches the Impersonation Attempts Keyword Matching Was Built to Miss
Domain Monitor's detection engine has been rebuilt to catch impersonation domains that keyword matching was never built to find. This release covers the new evidence-based matching engine, per-keyword Low, Medium and High thresholds, and what's coming next as the improvements roll out in stages.

Domain Monitor's detection engine has been rebuilt from the ground up. The result is a significant jump in the range of impersonation domains identified, combined with new per-keyword controls that put precision in the hands of the teams using it.
Key Takeaways
- A rebuilt matching engine scores every new domain on the strength of the evidence, catching deliberately disguised look-alikes that keyword rules were never built to detect
- Each monitored keyword can now be set to a Low, Medium or High matching threshold, putting granular control over sensitivity in your hands, term by term
- The improvements are rolling out in stages now; contact your account manager to enable them or review your keyword configuration
Keyword-based matching has an inherent limitation: it treats a hit as a binary decision, present or not present, with no way to account for how deliberately a domain has been constructed to evade detection. That limitation is what this release addresses.
A rebuilt matching engine.
Every newly registered domain is now broken into its real component words and tested against several matching methods, with the result scored on the strength of the evidence rather than judged as a simple match or non-match. This closes a gap that keyword rules have consistently left open: brand names split across a dot or hyphen, single-character typosquats, punycode and homoglyph substitutions, and recognised phishing structures such as secure-brand-login are all now identified. Detection runs across the full daily zone file feed of new domain registrations, so the gain is in breadth of coverage as well as precision of matching.
"Keyword matching on its own was never going to keep pace with how deliberately these domains are constructed," said Rob Campbell, Head of Product at CYJAX. "Scoring the evidence rather than just checking for a keyword hit means we're catching the domains that were built specifically to slip past that kind of rule."
Threshold control by keyword.
Each monitored keyword can now be set to a Low, Medium or High matching threshold, giving direct control over how aggressively each term is monitored. Distinctive brand terms can be set low, to surface even weak variations. Short or generic terms can be set high, so only near-exact impersonation is raised. The result is precision tuned term by term, not one blunt setting applied across an entire watchlist.
Availability.
These improvements are being released in a staged roll-out. To enable them on your account, or to review your keyword configuration, speak to your account manager.
What's next.
Work is already underway on machine enrichment for flagged domains: collecting screenshots, WHOIS and DNS information where available, and using that data to categorise and score domains automatically.
Next steps
To enable the updated Domain Monitor detection or review your keyword thresholds, contact your account manager.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.



