detection / lookalike handles scored by risk
Fake account detection by username
Fake account detection by username means generating every lookalike of a real handle, checking which of them exist as public profiles, and ranking them by how likely they are to be impersonation. UsernameLookup does this across 300+ sites and keeps evidence for each suspicious account.
The signals a fake handle gives away
Impersonators need people to misread a name for a second. That constraint makes their handles predictable, and predictable handles can be generated and checked before anyone falls for them.
Authority words
Names ending in _support, _help, _official, _care or _verify try to look like the service desk. A real brand rarely needs them.
Lookalike characters
Zero for o, 1 for l, rn for m. In a busy feed or a small phone font these read as the original name.
Keyboard slips
A neighbour key swapped or doubled. These catch people who type a handle from memory into a search box.
Extra punctuation
A dot or underscore in the middle of the brand. Easy to miss, and allowed on most platforms.
Prefixes that claim reality
real, the, its, iam, official in front of the name, a common pattern for fake creator and executive accounts.
Recent appearance
A lookalike that did not exist at the last scan and appears right after a launch, a sale or an outage deserves a look first.
How suspicious accounts are ranked
Every variant gets a risk score from 0 to 100 according to the pattern that produced it. The score is deterministic: the same handle always scores the same way, so your team can trust the ordering and explain it to a platform.
The score is a sorting tool, not a verdict. A fan account called brand_official_fans may be harmless. The case board shows the public page so a reviewer decides in seconds.
| Pattern | Base risk | Typical example |
|---|---|---|
| Authority suffix | 85 | northwind_support |
| Homoglyph | 80 | n0rthwind |
| Authority prefix | 75 | realnorthwind |
| Keyboard typo | 65 | northwinf |
| Separator | 60 | north.wind |
| Exact name elsewhere | 30 | northwind |
Evidence that survives a deleted account
Impersonators rename and delete accounts as soon as they sense a report coming. A screenshot taken by hand three days later often shows nothing. That is why each finding stores a snapshot at the moment of detection: the profile URL, the timestamp, the HTTP status and the page title.
On the Investigator plan and above you can add case notes, keep the history of every run and export a PDF report. When a platform asks for proof, you attach the snapshot and the report instead of rebuilding the story from memory.
For one-off checks of a single handle, a reverse username lookup shows every public profile using that exact name, which is often the fastest way to see whether a suspicious account is part of a wider pattern.
- URL
- instagram.com/northwind_help
- Timestamp
- 2026-10-08 14:32 UTC
- HTTP status
- 200
- Page title
- Northwind Help Desk
- Pattern
- suffix _help
- Case status
- reviewing
Example snapshot. Real snapshots are captured live by each scan.
Teams that check for fake accounts every week
Brand and social teams
Catch fake support accounts before customers message them, and keep a record of every report filed. See brand impersonation monitoring for the hourly brand plans.
Trust and safety teams
Check whether a new signup copies a known brand or creator handle, through the dashboard or the API, before the account goes live on your own platform.
Creators and founders
Watch your own handle and the handles of key people for copies that ask followers for money or promise giveaways.
What detection by username cannot tell you
A lookalike handle is a signal about the name, not proof of intent. Detection does not read private messages, does not look behind an account, and never tries to find out who operates it. It surfaces candidates and the public evidence, and a person decides.
People can remove their own username from our results through the opt-out page. Using results to harass anyone is forbidden by our acceptable use policy.
Questions about fake account detection
How can you tell a fake account from its username alone?
The handle carries more signal than people expect. A name that copies a brand with a homoglyph, a keyboard typo or a support suffix, and that appeared recently on a platform where the real brand already has an account, is a strong impersonation candidate. We score those patterns and show the public profile so a person can confirm.
What does the risk score mean?
It is a number from 0 to 100 based on the variant pattern. Support and official style suffixes score highest, homoglyphs next, then typos and separators. An exact copy of your handle on a new platform scores lower, because it is often a squatted name rather than an active scam.
Can fake account detection run on usernames that are not brands?
Yes. Pro and Investigator plans watch personal handles, for example a founder, a creator or an executive. Brand Monitoring adds executive impersonation watch for up to 10 named people alongside 10 brands.
Does the tool read private data to decide if an account is fake?
No. It only looks at public profile addresses and the public page that answers there: HTTP status, page title, display name and avatar. It never logs in and never tries to identify who runs the account.
Find lookalikes of your handle now
Search the name once across 300+ sites, then keep watching it for new fake accounts.