Dev.to
7/12/2026

Catching AI-Cloned Phishing Sites Before Customers Do
Short summary
AI tools can now clone websites pixel-for-pixel in under a minute, making visual inspection useless for phishing detection. The author describes a pipeline that generates likely attacker domain variations, checks DNS and WHOIS data, and crawls live sites to capture evidence like DOM snapshots and certificate chains. The approach catches lookalike domains before they go live, though shared-platform subdomains and takedown processes remain manual gaps.
- •AI cloning tools make visual detection of phishing sites obsolete
- •Detection pipeline generates domain variations, checks DNS/WHOIS, crawls live sites for evidence
- •Shared-platform subdomains and takedown workflows remain unsolved challenges
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



