Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Malware Analysis
  3. dnstwist

dnstwist

Apache-2.0Python20250130

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation.

Visit WebsiteGitHubGitHub
5.7k stars849 forks0 contributors

What is dnstwist?

dnstwist is a domain name permutation engine that generates and analyzes variations of domain names to detect potential cyber threats. It helps security professionals identify homograph phishing attacks, typo squatting attempts, and brand impersonation by checking which lookalike domains are registered and potentially malicious.

Target Audience

Security researchers, penetration testers, brand protection teams, and IT security professionals who need to monitor domain name abuse and protect against phishing attacks.

Value Proposition

Developers choose dnstwist because it provides comprehensive domain permutation capabilities with multiple detection methods (DNS, WHOIS, SSDeep, GeoIP) in a single open-source tool, making it more accessible and customizable than commercial alternatives.

Overview

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Use Cases

Best For

  • Monitoring brand domains for typo squatting and impersonation
  • Detecting homograph phishing attacks using internationalized domain names
  • Security research on domain name abuse patterns
  • Penetration testing of organization's domain security
  • Proactive threat intelligence gathering for cybersecurity teams
  • Identifying cloned websites used in phishing campaigns

Not Ideal For

  • Teams requiring automated, real-time domain monitoring with instant alerts
  • Non-technical users or organizations without dedicated security expertise
  • Projects with strict performance constraints needing fast, lightweight domain checks
  • Environments where graphical user interfaces are mandatory for daily operations

Pros & Cons

Pros

Extensive Permutation Algorithms

Generates thousands of domain variations using fuzzing and dictionaries, ensuring broad coverage for detecting typo squatting and impersonation attempts.

Homograph Attack Detection

Specifically identifies IDN homograph attacks through character substitution, addressing a critical phishing vector that many tools overlook.

Integrated Threat Intelligence

Combines DNS resolution, WHOIS lookup, SSDeep hashing, and GeoIP in one tool, providing a holistic view of potential threats from registered domains.

Open-Source Flexibility

As an open-source project, it allows for customization and integration into existing security workflows without vendor lock-in, unlike commercial alternatives.

Cons

CLI-Only Interface

Operates solely through command-line, which can be a barrier for non-technical users or teams preferring graphical tools for ease of use.

Resource-Intensive Operations

Comprehensive checks like SSDeep fuzzy hashing and multiple WHOIS queries can be slow and require significant computational resources, impacting performance on large scans.

Setup Complexity

Requires installation of Python dependencies and configuration of external services, which may involve a non-trivial setup process for beginners or in constrained environments.

Frequently Asked Questions

Quick Stats

Stars5,713
Forks849
Contributors0
Open Issues9
Last commit1 year ago
CreatedSince 2015

Tags

#python-tool#dns-analysis#osint#dns#fuzzing#phishing-detection#threat-intelligence#domain-security#scanner#phishing#cybersecurity#idn#threat-hunting#domains

Built With

P
Python

Links & Resources

Website

Included in

Malware Analysis13.6k
Auto-fetched 7 hours ago

Related Projects

mailcheckermailchecker

:mailbox: Cross-language temporary (disposable/throwaway) email detection library. Covers 55 734+ fake email providers.

Stars1,899
Forks307
Last commit3 days ago
MachinaeMachinae

Machinae Security Intelligence Collector

Stars537
Forks101
Last commit1 month ago
IPinfoIPinfo

Searches various online resources to try and get as much info about an IP/domain as possible.

Stars102
Forks25
Last commit12 years ago
MaltegoVTMaltegoVT

A set of Maltego transforms for VirusTotal Public API v2.0. This set has the added functionality of caching queries on a daily basis to speed up resolutions.

Stars82
Forks21
Last commit10 years ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub