dnstwist
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
Decision gist · record as of 2026-08-14
Yes, if you need to monitor for domain-based threats. The tool is well-maintained despite aging status, has no external dependencies, and offers both CLI and programmatic interfaces. Install the base package for core fuzzing; add optional dependencies only if you need phishing detection or GeoIP features. No known vulnerabilities.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Phishing detection features (--phash) require Chromium browser installed; GeoIP features require GeoLite2 database and environment variable setup.
- Low install friction with no runtime dependencies.
- Maintenance status is aging—last release was 561 days ago, though the repository remains active with recent commits and substantial community interest (5727 stars).
License · maintenance · safety
ASL 2.0 (permissive) — Licensed under Apache Software License (ASL 2.0), a permissive license allowing commercial use, modification, and distribution with minimal restrictions.
last release 2025-01-30 (561 days) · last repo commit 2025-04-15 · 5,727 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 119,741 downloads/mo, #12,058 on PyPI
Alternatives
Verify before relying
pip install dnstwist
import dnstwist
data = dnstwist.run(domain='example.com', registered=True, format='null')- Whether optional features (phishing detection, GeoIP, screenshots) require additional system dependencies beyond Python
- Specific Python version requirements, as the fact sheet does not specify a minimum version
- Performance characteristics when processing very large domain lists or with concurrent requests
What it is and what it does
dnstwist is a domain fuzzing tool that generates permutations of a given domain name to uncover potentially malicious lookalike domains. It applies multiple fuzzing algorithms (homoglyph, hyphenation, transposition, and others) to create variants and then verifies which ones are registered via DNS lookups. The tool is designed to help organizations identify typosquatting, phishing, and brand impersonation threats targeting their domain.
Beyond basic domain enumeration, dnstwist offers advanced threat detection: it can compare HTML source code of discovered domains against the original using fuzzy hashing (ssdeep or TLSH) to detect phishing sites with similar content, capture and compare web page screenshots using perceptual hashing when Chromium is available, detect rogue MX hosts, and perform GeoIP lookups on resolved addresses. Results can be exported to CSV or JSON, and the tool exposes a Python API for programmatic use.
Use it for
- Monitor for typosquatted domains targeting your organization and alert on newly registered lookalikes
- Conduct phishing campaign reconnaissance by generating domain variants and checking for active phishing pages
- Audit brand impersonation risk by discovering domains that visually or semantically resemble your legitimate domain
- Integrate domain threat intelligence into security workflows via the Python API to automate threat detection
- Perform passive domain enumeration to generate permutation lists without DNS queries for offline analysis
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to monitor for domain-based threats.
The tool is well-maintained despite aging status, has no external dependencies, and offers both CLI and programmatic interfaces. Install the base package for core fuzzing; add optional dependencies only if you need phishing detection or GeoIP features. No known vulnerabilities.
Install
dnstwist on PyPI
Before you install
Low install friction with no runtime dependencies. Maintenance status is aging—last release was 561 days ago, though the repository remains active with recent commits and substantial community interest (5727 stars).
Phishing detection features (--phash) require Chromium browser installed; GeoIP features require GeoLite2 database and environment variable setup.
License in practice
Licensed under Apache Software License (ASL 2.0), a permissive license allowing commercial use, modification, and distribution with minimal restrictions.
Quickstart
pip install dnstwist
import dnstwist
data = dnstwist.run(domain='example.com', registered=True, format='null')
Verify before relying
- Whether optional features (phishing detection, GeoIP, screenshots) require additional system dependencies beyond Python
- Specific Python version requirements, as the fact sheet does not specify a minimum version
- Performance characteristics when processing very large domain lists or with concurrent requests
Package facts
| License | ASL 2.0 permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 561 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 119,741 / month, #12,058 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3 |
Evidence: dnstwist-20250130-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “domain typosquatting detection”
- dnstwistGenerates domain name permutations to detect typosquatting, phishing,…
- confusablesDetects and matches words that appear identical but use different…
- linkify-it-pyDetects and extracts URLs, email addresses, and custom protocol links…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also confusable-homoglyphs · domaintools-api · publicsuffix2 · tlds · tldextract · idna · tldparse · disposable-email-domains · boofuzz · safehttpx