DraftKings Sportsbook
Outtake
Private / Prepared for DraftKings

Eight suspicious URLs. One connected fraud operation.

Outtake’s Recon Agent expanded a targeted domain investigation into a map of DraftKings impersonation infrastructure, related campaigns, operator fingerprints, and the choke points that can dismantle more than one URL at a time.

Recon agent / campaign expansion Verified
DraftKings lookalike
eng-us-draftkings[.]com
DraftKings lookalike
en-draftkingscasino[.]com
DraftKings lookalike
us-draftkings[.]com
DraftKings lookalike
draftkingscasino.de[.]com
Shared staging proxy
100+ stagings

Campaign infrastructure exposed before cutover.

Registrar + DNS
15+ DK assets
Hosting + CDN
Shared cohorts
Operator graph
Cross-brand reuse
Eight seed URLs → connected campaignJuly 15, 2026 snapshot
20+
DraftKings domains
100+
Staged subdomains
40
Confirmed malicious
243
Leads parked
01 / Campaign architecture

Find the campaign behind the domain.

The report connected lookalike domains to shared staging, registrar, hosting, redirect, affiliate, and operator signals. That changes the work from one-by-one removal into infrastructure-led disruption.

Certificate transparency lead1–2 days
Staging certificate
new-domain[.]staging
Live campaign
customer-facing domain

Monitoring the operator’s staging pattern creates an early-warning signal before the next impersonation property reaches customers.

01
Registrar

Registrar concentration

15+ DraftKings campaign domains

02
Early warning

Wildcard staging proxy

100+ campaign stagings

03
Infrastructure

Shared CDN + DNS

US and EU cohorts

04
Expansion

Hosting + nameservers

Connected Stake cluster

02 / Autonomous DRP workflow

Detect the signal. Investigate the system. Dismantle the operation.

Outtake connects discovery, investigation, remediation, and recurrence monitoring in one case, with workflows your team controls.

01
Search the full domain surface

Detect

Continuously combine registration, DNS, certificate transparency, hosting, redirect, scan, and open-web signals to find lookalikes and the infrastructure behind them.

Typos + brand terms
CT and DNS changes
Redirect destinations
Global external-signal footprint
X logo
Facebook logo
Instagram logo
TikTok logo
YouTube logo
Telegram logo
WhatsApp logo
Reddit logo
Threads logo
Truth Social logo
Mastodon logo
Meta logo
Bluesky logo
LinkedIn logo
Google logo
Bing logo
Dark webDomainsAds

Outtake searches across the external surfaces where impersonation campaigns appear, connect, and recur.

Recon Agent investigation snapshotJuly 15, 2026
66
Nodes
64
Links
40
Confirmed malicious
243
Leads parked
Critical finding

A wildcard staging proxy exposed a 100+ domain footprint and a repeatable early-warning signal for what could launch next.

Private briefing

Turn one suspicious domain into the map for what comes next.

Review the campaign, the intervention points, and how Outtake can extend the same workflow across domains and social impersonation.