Pivot domains by shared DNS infrastructure
Operators reuse nameservers across their whole portfolio. Enter a nameserver to see every domain that uses it, or a domain to see its nameservers and the sibling domains that share them, likely run by the same hands. Built from ICANN zone data, no registrant details needed. Shared-hosting nameservers (Cloudflare, GoDaddy) are flagged, not treated as ownership.
Enter a nameserver hostname to list every domain that points at it.
Why nameserver pivoting finds an actor's other domains
When someone registers a batch of lookalike or phishing domains, they usually point them at the same DNS infrastructure, either their own nameservers or a small hosting account. Registrant details are redacted under GDPR, but nameservers are public in the DNS zone and can't be hidden. So pivoting from one known-bad domain to the others on its nameservers is often the fastest way to surface an operator's full portfolio, including domains they've registered but not yet weaponized.
What "distinctive" means here
A nameserver used by millions of unrelated domains (Cloudflare, GoDaddy, parking services) tells you nothing about ownership, so those are filtered out and shown as hosting-tier. The signal lives in the distinctive nameservers, used by a small, related set of domains. Sibling scoring weights rarer shared nameservers more heavily.
Pair it with the rest of your toolkit
Found a suspicious sibling? Run it through the phishing scan, check its SSL posture, or pivot on its registrant with reverse WHOIS. For continuous coverage of new lookalikes against your brand, see the Brand monitor plans.
Related free tools
Reverse WHOIS · Phishing scan · SSL grader · Credential exposure