Skip to content
UsernameLookup

detection / lookalike handles scored by risk

Fake account detection by username

Fake account detection by username means generating every lookalike of a real handle, checking which of them exist as public profiles, and ranking them by how likely they are to be impersonation. UsernameLookup does this across 300+ sites and keeps evidence for each suspicious account.

Trust and safety analyst reviewing account reports at a desk with a colleague
01 signals

The signals a fake handle gives away

Impersonators need people to misread a name for a second. That constraint makes their handles predictable, and predictable handles can be generated and checked before anyone falls for them.

suffix

Authority words

Names ending in _support, _help, _official, _care or _verify try to look like the service desk. A real brand rarely needs them.

homoglyph

Lookalike characters

Zero for o, 1 for l, rn for m. In a busy feed or a small phone font these read as the original name.

typo

Keyboard slips

A neighbour key swapped or doubled. These catch people who type a handle from memory into a search box.

separator

Extra punctuation

A dot or underscore in the middle of the brand. Easy to miss, and allowed on most platforms.

prefix

Prefixes that claim reality

real, the, its, iam, official in front of the name, a common pattern for fake creator and executive accounts.

new

Recent appearance

A lookalike that did not exist at the last scan and appears right after a launch, a sale or an outage deserves a look first.

02 scoring

How suspicious accounts are ranked

Every variant gets a risk score from 0 to 100 according to the pattern that produced it. The score is deterministic: the same handle always scores the same way, so your team can trust the ordering and explain it to a platform.

The score is a sorting tool, not a verdict. A fan account called brand_official_fans may be harmless. The case board shows the public page so a reviewer decides in seconds.

Risk score by lookalike pattern
Pattern Base risk Typical example
Authority suffix 85 northwind_support
Homoglyph 80 n0rthwind
Authority prefix 75 realnorthwind
Keyboard typo 65 northwinf
Separator 60 north.wind
Exact name elsewhere 30 northwind
03 evidence

Evidence that survives a deleted account

Impersonators rename and delete accounts as soon as they sense a report coming. A screenshot taken by hand three days later often shows nothing. That is why each finding stores a snapshot at the moment of detection: the profile URL, the timestamp, the HTTP status and the page title.

On the Investigator plan and above you can add case notes, keep the history of every run and export a PDF report. When a platform asks for proof, you attach the snapshot and the report instead of rebuilding the story from memory.

For one-off checks of a single handle, a reverse username lookup shows every public profile using that exact name, which is often the fastest way to see whether a suspicious account is part of a wider pattern.

evidence snapshot captured at detection
URL
instagram.com/northwind_help
Timestamp
2026-10-08 14:32 UTC
HTTP status
200
Page title
Northwind Help Desk
Pattern
suffix _help
Case status
reviewing

Example snapshot. Real snapshots are captured live by each scan.

04 who uses it

Teams that check for fake accounts every week

Brand and social teams

Catch fake support accounts before customers message them, and keep a record of every report filed. See brand impersonation monitoring for the hourly brand plans.

Trust and safety teams

Check whether a new signup copies a known brand or creator handle, through the dashboard or the API, before the account goes live on your own platform.

Creators and founders

Watch your own handle and the handles of key people for copies that ask followers for money or promise giveaways.

05 limits

What detection by username cannot tell you

A lookalike handle is a signal about the name, not proof of intent. Detection does not read private messages, does not look behind an account, and never tries to find out who operates it. It surfaces candidates and the public evidence, and a person decides.

People can remove their own username from our results through the opt-out page. Using results to harass anyone is forbidden by our acceptable use policy.

06 faq

Questions about fake account detection

How can you tell a fake account from its username alone?

The handle carries more signal than people expect. A name that copies a brand with a homoglyph, a keyboard typo or a support suffix, and that appeared recently on a platform where the real brand already has an account, is a strong impersonation candidate. We score those patterns and show the public profile so a person can confirm.

What does the risk score mean?

It is a number from 0 to 100 based on the variant pattern. Support and official style suffixes score highest, homoglyphs next, then typos and separators. An exact copy of your handle on a new platform scores lower, because it is often a squatted name rather than an active scam.

Can fake account detection run on usernames that are not brands?

Yes. Pro and Investigator plans watch personal handles, for example a founder, a creator or an executive. Brand Monitoring adds executive impersonation watch for up to 10 named people alongside 10 brands.

Does the tool read private data to decide if an account is fake?

No. It only looks at public profile addresses and the public page that answers there: HTTP status, page title, display name and avatar. It never logs in and never tries to identify who runs the account.

Find lookalikes of your handle now

Search the name once across 300+ sites, then keep watching it for new fake accounts.