DigiGuardiansDigiGuardians

Technology

Domain Monitoring Technology

Domain monitoring tracks the new names a pirate site moves to after blocking or delisting, and the lookalikes that imitate a rights holder, so each one is tied to a known case instead of rediscovered from scratch.

August 11, 20264 min read

In anti-piracy work, domain monitoring answers the same question over and over: where a known site has moved to since the last check. Pirate streaming and download sites build an audience around a brand name and a familiar layout. The domain underneath is the least permanent part. When it is blocked by internet providers in one country, delisted by search engines, suspended by a registrar or flagged by browsers as unsafe, the operator moves to a new one and tells the audience how to follow.

The hop pattern

Domain hops follow recognisable habits. The site name stays and only the extension changes. A digit or letter is appended or incremented. A word such as "new", "official" or "proxy" is added. Several domains are kept live at the same time as mirror sites, with traffic shifted between them when one is blocked. Many operators also keep a stable landing domain or social channel whose only job is to publish the current address.

A domain monitoring system models those habits explicitly. For each tracked site it holds the name stem, its known variants and the extensions it has used, and it generates the candidates the operator is most likely to register next. Those candidates are checked repeatedly, because the replacement is often registered well before it is switched on.

Where new domains turn up

No single source sees everything, so several are combined:

  • Registry zone data. Many generic top-level domain registries make their zone files available to approved users, and comparing successive files reveals newly registered names. Country-code registries vary widely in what they publish.
  • Certificate Transparency logs. A new site enabling HTTPS usually leaves a public certificate record for its hostname.
  • Redirects from known domains. The old domain often forwards visitors to the new one for a while, which is the clearest link available.
  • The operator's own channels. Telegram channels, social accounts and status pages announce new addresses to users.
  • Search results. A new domain starts ranking for the same title queries the old one held.

Confirming it is the same site

A name is not proof. Someone may register a similar name to ride on the original's reputation, or to serve malware to its visitors. Before a new domain is attached to an existing case, it is compared with the known site on evidence that is hard to match by accident: the page template and its custom elements, analytics and advertising identifiers in the code, the catalogue and how it is organised, the player and file hosts it uses, and any contact or payment details it displays. A domain that matches on several of these is treated as a continuation. A domain that matches on name alone is tracked as a separate target.

The record for each domain should show when it was first seen, which source revealed it and what evidence linked it, so later actions can demonstrate why it was treated as part of the same operation.

Why speed matters where blocking is used

In countries where courts or authorities order internet providers to block named pirate domains, an order covering a domain the site has already abandoned achieves little. Some jurisdictions allow orders to be extended to new domains serving the same site, sometimes described as dynamic blocking, but the evidence that the new domain really is the same site still has to be assembled and presented. The rules on what can be extended, and how, vary considerably between jurisdictions. Search engine delisting works at the level of specific URLs, so a new domain likewise needs new requests.

Domain monitoring supplies that evidence quickly and in a consistent form. It also keeps source-level enforcement on track: a hopped site usually keeps the same file hosts and embed sources, so notices aimed at the source keep working even when domain-level measures lag behind. The trade-off is outlined in source takedown vs link removal.

Lookalikes on the other side

The same machinery can face the other way and watch for domains that imitate the rights holder rather than the pirate: unofficial "watch free" portals using a broadcaster's name, fake download pages for a new release, or phishing pages copying a subscription service. The discovery sources are the same. The matching rules are built around the client's own brand and product names, with its real domains and partners excluded.

DigiGuardians tracks mirror domains and re-uploads and handles them as they appear, as part of ongoing protection.

  • Domain Intelligence
  • Technology

Keep reading.

Piracy moves fast. Takedown should move faster.

Tell us what you protect. We'll map where your titles leak and show you what we'd remove first.

First report free · 14-day trial · No obligation

Stay ahead of the pirates.

No spam, just the takedowns, threats and reports worth your inbox.