Pivot map
Use this map to decide whether DNS twister accepts the lead you are holding, and what kind of lead it may return for the next step.
Pivot from here
Outputs from DNS twister can become inputs for the next tool. These are the most relevant follow-on pivots in the library.
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Investigator Use
DNS Twister is a free domain intelligence tool that detects typosquatting, domain permutations, and homoglyph variants of a target domain. By generating and analyzing variations of a domain name — including common misspellings, character substitutions, and internationalized homoglyphs — DNS Twister helps investigators identify domains that may be used for phishing, brand impersonation, or traffic interception.
What investigators use DNS Twister for: discovering domains that impersonate a target organization for phishing campaigns, monitoring for typosquatting threats against a brand, identifying domains registered by threat actors that closely resemble legitimate domains, and tracking when permutation domains are newly registered and configured.
What DNS Twister exposes: algorithmically generated domain permutations for any input domain, live DNS resolution status for each permutation, phishing risk scores based on registration patterns, MX record presence indicating whether permutations have been configured to send email, and parked versus active domain status.
DNS Twister implements multiple permutation algorithms: character substitution (replacing o with 0), character deletion, character insertion, character transposition, homoglyph substitution (using Unicode characters that visually resemble ASCII letters), and bitsquatting (exploiting single-bit errors in domain name transmission). Each technique represents a different type of domain confusion attack.
For brand protection investigations: submit the target domain and review permutations that are actively registered and have MX records — the combination of registration and mail configuration is a strong indicator of phishing intent. Domains with MX records but no web content are frequently used as phishing infrastructure waiting to be activated.
Proactive monitoring: DNS Twister's phishing detection feature can alert on newly registered permutations, allowing defensive teams to act before phishing campaigns go live. In an OSINT context, newly registered similar domains following a news event or corporate announcement are particularly suspicious.
In a workflow: run DNS Twister at the beginning of any brand protection or phishing investigation. Take all registered permutations with MX records and query them in PhishTank, VirusTotal, and SecurityTrails. For newly registered permutations, check WHOIS registration data for registrant patterns that link multiple fake domains to the same threat actor.
Before You Pivot
Capture the target, search terms, and why this source is relevant before you leave the page.
Archive volatile pages, save screenshots, and keep timestamps for anything that may change.
Treat one tool as a lead source. Confirm important findings with independent sources.
Related tools
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
Free online network tools, including traceroute, nslookup, dig, whois, ping, and our own Domain Dossier and Email Dossier. Works with IPv6.
An open source intelligence tool to crawl the graph of certificate Alternate Names
Finds certificates and subdomains using Certificate Transparency data. An alternative to crt.sh that presents the information a bit differently.
DNS History archives historical DNS records, letting investigators track IP changes, hosting migrations, and infrastructure pivots over time.
Free DNS, WHOIS, and email-authentication lookups for any domain: SPF analysis with the 10-lookup limit check, DKIM selector discovery, DMARC checks, email header analysis, and blacklist checks. Results explain in plain English what each record means. No account needed for basic lookups; free API tier available.