Brand Protection
Brand Protection allows you to proactively identify and mitigate domain impersonation and phishing attacks. By monitoring newly registered domains and visual assets across the Internet, Cloudflare helps protect your brand's reputation and prevents your customers or employees from submitting sensitive information to fraudulent sites.
Common threats include:
- Typosquatting ↗: For example, typing
cloudfalre.cominstead ofcloudflare.com. - Concatenation of services (
cloudflare-service.com) often registered by attackers to trick unsuspecting victims into submitting private information such as passwords. - Homoglyph attacks ↗ that use lookalike characters to trick unsuspecting victims.
Cloudflare Brand Protection offers two distinct methods for monitoring impersonation: domain search and logo search.
Search for domains based on text patterns, misspellings, or service combinations.
To start searching for new domains that might be trying to impersonate your brand:
-
In the Cloudflare dashboard, go to the Brand Protection page.
Go to Brand protection -
In String query, provide a name for your query. You can add multiple brand phrases on the same query, and the results will generate matches for all of those. Once you entered the string queries, select Search matches.
-
In the Character distance, select from
0-3. This defines how many characters a result can differ from your string (for example, a distance of 1 would catchclpudflare.com). The number of characters the results can differ from your domain. -
You can select Save query to monitor it in the future and perform other actions, such as delete, clone and set up alerts, according to your Paid plan limits.
-
To export all matches from a saved query, select your Query name > select the three dots > Export matches.
In the section Monitor Strings, you can check all the string queries that you selected to monitor. You can delete, clone, or create notifications for a string query. Refer to Brand Protection Alerts to set up notifications.
Logo search uses computer vision to detect domains using your visual assets, even if the domain name does not contain your brand string.
To set up a new logo query:
- Select Monitor Logos and select Add logo.
- Add a name for your query and upload your logo. Only the
.png,.jpeg, and.jpgfile extensions are supported. - Set the threshold: Set a match threshold (the minimum is 75%). A higher score ensures high-precision matches, while a lower score catches remixed or slightly altered versions of your logo.
- Select Save logo. The system will now scan newly detected infrastructure for visual matches.
The browser will return to the Monitored Logos page, where you can access your query and configure notifications.
In this section, the dashboard displays:
- Domain overview where you can request to change categorization and view the resolution history of your domain for up to seven days.
- WHOIS that provides details about the date the domain was created, registrant and nameservers.
- Domain history that provides information on the domain category and when it was last changed. Refer to Investigate threats for more details.
- URL Reports that provides information on any reported URL.
To investigate a string query:
- Go to the Monitor Strings or Monitor Logos section to view all your queries.
- Select a monitored query to inspect all the domains that matched your query.
- Next to the domain, select Domain or URL. This will trigger a search on the Investigate section in a separate tab. URL scanner will also be triggered from Brand Protection through Security Center > Investigate. You will also have access to a report which will be generated automatically. The report will display screenshots of the matched domain, and the registrar of your domain.
To submit abuse reports directly from the dashboard:
-
In the Cloudflare dashboard, go to the Brand Protection page.
Go to Brand protection -
Go to Monitor Strings, select the query you want to report.
-
Select Report to Cloudflare.
-
Fill in the details to submit an abuse report.
-
Select Submit.
To view abuse reports, in the Cloudflare dashboard, go to the Abuse Reports page.
Go to Abuse reportsYou can review abuse reports against your zones and any mitigations taken against reports in response.
You can also Request review of most mitigations.
The Brand Protection API allows for programmatic management and integration with your SOC ↗ or SIEM ↗. Using the Brand Protection API, you can:
- Manage queries: Create, edit, or delete string and logo queries.
- Data retrieval: Read and download matches for automated ingestion.
- Query editing: Update existing query parameters without losing historical data.
Brand Protection integrates with Cloudflare's ANS (Alerts Notification Service) to provide configurable alerts when new domains are detected.
Any matches that are found during the new domain search are then inserted into an internal alerts table which triggers an alert for the user. This allows you to receive real-time notifications and take immediate action to investigate and potentially block any suspicious domains that may be attempting to impersonate your brand.
Brand Protection Alerts
Who is it for?Customers who want a summary of activity related to Brand Protection.
Other options / filtersYou can set up Brand Protection Alerts on individual monitored queries. For more details, refer to Brand Protection Alerts.
Included withProfessional plans or higher.
What should you do if you receive one?Investigate and potentially block any suspicious domains that may be trying to impersonate your brand.
Brand Protection Digest
Who is it for?Customers who want a summary of activity related to Brand Protection.
Other options / filtersYou can set up Brand Protection Digest on individual monitored queries. For more details, refer to Brand Protection Alerts.
Included withProfessional plans or higher.
What should you do if you receive one?Investigate and potentially block any suspicious domains that may be trying to impersonate your brand.
Logo Match Alerts
Who is it for?Customers who want to receive a notification when the Brand Protection system detects a new domain which is using the uploaded logo and might be infringing copyright.
Other options / filtersYou can select the query that you want to be alerted on.
Included withEnterprise plans.
What should you do if you receive one?Review the domains and URLs that are potentially impersonating your brand.
Security Insights
Who is it for?Customers who want to receive notifications based on security insights findings.
Other options / filtersYou can select the insight(s) you want to be alerted on.
Included withAll Cloudflare plans.
What should you do if you receive one?Review the insight and decide whether you want to resolve it, archive it, or export it.
Abuse report
Who is it for?Customers who want to be alerted in the event that an abuse report is filed against their website.
Other options / filtersYou can filter the reports based on date, report status, report type, and domain.
Included withAll Cloudflare plans.
What should you do if you receive one?View our guidance on customer abuse report obligations and more information on how to view and submit abuse reports.
To set up a Brand Protection Alert:
-
Go to Monitor Strings and locate the query for which you would like to create notifications.
-
Select alerts. This should redirect you to the Add Notification page, where you can configure what you want to be notified about, and how.
-
Create a notification name, add a description (optional), and select the monitored queries. You can also add a Webhook, and a notification email. You can add multiple email addresses.
-
Select Save.
Manage your notifications in the All notifications tab. You can disable, edit, delete, or test them.
- Self-serve users can subscribe directly to add monitoring capacity to their account.
- You may only use the Brand Protection search tools to search for domains that may be attempting to impersonate your brand or a brand that has authorized you to conduct such search on its behalf.