Skip to main content
Do not wait for the angry customer email about an order they never placed.Scan your brand, free
ATCHER.AI
Scan my brand
Back to guides

We scanned 25 DTC brands for clones

Davis PaipaFounder of KatcherPublished Our data

On 13 September 2026 we pointed the production scanner at 25 direct to consumer brands on the live internet, in one afternoon. Here are the figures, and the parts that are more interesting than the figures.

Across 25 brands in one afternoon we generated and checked 1,480 look-alike names, swept 3,681 certificate log entries, found 230 that resolved in DNS and recorded 66 live storefronts for review. Three brands came back clean. That last number matters most: a scan that cannot return nothing is not measuring anything.

The run

Brands scanned25
Look-alike names generated and checked1,480
Certificate log entries swept3,681
Candidate names that resolved in DNS230
Live storefronts recorded for review66
Brands that came back clean3

No brand names or domains from the run are published. That information belongs to the brands it concerns.

The number that matters is three

Twenty two of twenty five brands had at least one live storefront worth reviewing. That is the alarming number and it is the one that gets quoted.

The useful number is the other one. Three brands came back clean, and a scan that is incapable of returning nothing is not measuring anything. If every brand had come back with findings, the honest conclusion would have been that our thresholds were too loose, not that the internet is uniformly on fire.

A clean result is a product feature. It is also the outcome we tell people to expect if it is what we find.

Most of what a scan surfaces is noise

1,480 names were generated and checked. 230 of those resolved in DNS at all. 66 were live storefronts worth a human look.

So roughly one in six names that resolved was worth reviewing, and roughly one in twenty-two names generated. Everything else was one of four things:

  • Parked pages and domains for sale. Registered speculatively, serving an advertising page, doing nothing to anyone.
  • Dead hosts. A certificate issued, nothing ever put behind it.
  • Older than the brand. A domain registered before the brand existed cannot be a copy of it. Recorded and flagged rather than discarded, because the fact that it was considered is part of the record.
  • The brand's own stores. Regional storefronts and old campaign domains look exactly like suspects in a list of names.

This is the part of the problem that determines whether monitoring is useful or exhausting. A system that forwards 230 names to a merchant has not done the work. It has moved the work.

Certificate logs found what permutations could not

Two discovery methods ran side by side: generated permutations of each brand name, and a sweep of public certificate transparency logs.

The permutation list finds names you can imagine. The certificate sweep finds names that exist. They overlap, and the second reaches things the first cannot, because a permutation generator can only produce variations someone thought to encode.

The mechanism is public and free and any merchant can run it by hand. It is written up in the guide on certificate transparency.

The shape of a finding

The signals that repeated across the run, in rough order of how much weight they carry:

  1. Domain age against brand age. A domain registered weeks ago selling a brand that has traded for years. On its own it means little, and combined with anything else it means a great deal.
  2. Images served from the brand's own content delivery network. Not copied: hotlinked. The store did not even host its own copy of the photographs. This is the single hardest signal to explain innocently.
  3. Page titles and product descriptions reused word for word, occasionally including errors the brand had since corrected on its own site.
  4. Policy pages missing or erroring, and no contact address anywhere.

An illustrative finding in this shape, with the brand and domain replaced by placeholders, is on the homepage.

What this run does not show

Being honest about the limits is the point of publishing it at all:

  • 66 is storefronts recorded for review, not infringements. What survives human review is a smaller number. A look-alike name is not evidence of anything.
  • One afternoon is a snapshot. Copies appear and disappear on a scale of weeks, so a single run understates the total that existed over any longer period.
  • 25 brands is not a representative sample of anything. It is 25 brands.
  • We have taken nothing down. This is a measurement of what is out there, not a record of results.

Any brand can run this against its own domain and get the pack, which is the only way to check a claim like this properly.

Questions

Which brands were scanned?

We do not publish them. Naming a brand publishes the fact that it has copies, which is the brand's information to share and not ours. The figures here are aggregates across the run.

Does 66 storefronts mean 66 infringements?

No, and this is the most important caveat on the page. 66 is the number of live storefronts recorded for review. What survives review is smaller, because a look-alike name is not evidence of anything by itself.

How many brands came back clean?

Three of twenty-five. That number matters more than the copies, because it is the one that tells you the scan is capable of saying no. A tool that finds something for everyone is not measuring anything.

Can I see the raw data?

The per-brand packs belong to the brands. What is published here is the aggregate shape of the run, and any brand can generate its own pack for its own domain.