US 11,736,521 B2
Systems and methods for detecting domain impersonation
Simon Paul Tyler, Wiltshire (GB); Jackie Anne Maylor, Wiltshire (GB); Paul Sowden, London (GB); and Meni Farjon, Ramat Gan (IL)
Assigned to Mimecast Services Ltd., London (GB)
Filed by Mimecast Services Ltd., London (GB)
Filed on Sep. 18, 2018, as Appl. No. 16/134,317.
Claims priority of provisional application 62/581,860, filed on Nov. 6, 2017.
Prior Publication US 2019/0141077 A1, May 9, 2019
Int. Cl. H04L 9/40 (2022.01); G06F 21/51 (2013.01); G06F 16/907 (2019.01); G06F 21/60 (2013.01); G06F 21/44 (2013.01); H04L 61/4511 (2022.01)
CPC H04L 63/1483 (2013.01) [G06F 16/907 (2019.01); G06F 21/44 (2013.01); G06F 21/51 (2013.01); G06F 21/606 (2013.01); H04L 63/1416 (2013.01); G06F 2221/2119 (2013.01); H04L 61/4511 (2022.05)] 9 Claims
OG exemplary drawing
 
1. A system for domain name authentication, the system comprising:
at least one processor coupled to at least one memory containing instructions executable by the at least one processor to cause the system to:
maintain a database with a plurality of trusted domains;
analyze a domain associated with an undelivered message intended to be delivered to a recipient, wherein analysis of the domain comprises a comparison of the domain with one or more of the plurality of trusted domains;
determine that the domain is similar but not identical to at least one of the trusted domains based on the comparison of the domain with one or more of the plurality of trusted domains;
access at least one domain registration system to determine an identity of a registrar for the domain and an identity of a registrar for at least one of the trusted domains that are similar but not identical to the domain;
compare the identity of the registrar for the domain with the identity of the registrar for the least one of the trusted domains that are similar but not identical to the domain; and
flag the domain as being legitimate or flag the domain as being illegitimate based on whether the identity of the registrar for the domain is the same as or different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.