Ads — Unauthorised Advertiser Detection

Ads watches paid search results for a keyword — typically your brand or product name — and flags any advertiser whose destination isn't on your approved-domains list.

Setting it up

Add a keyword (e.g. your brand name, or "<brand> login") and a list of domains you're comfortable seeing bid on it — your own domains, and any approved affiliates or resellers. Everything else that shows up as a paid result gets flagged.

Why this exists as its own product, not part of Domains

Domains & Typosquat Monitoring catches attackers who register a lookalike domain. But a real, damaging pattern doesn't require registering anything at all: an attacker builds a phishing page on a free hosting platform — Google Sites, Notion, GitHub Pages, Vercel, dozens of others — and simply pays for a Google Ad pointing at it. There's no domain registration event for Certificate Transparency to catch, because the underlying domain (sites.google.com, notion.site, ...) has existed for years and belongs to a legitimate company.

Ads is the one product watching the ad itself, so it's the one place this attack shape gets caught. Any ad landing on a known free-hosting platform is flagged automatically, regardless of your approved-domains list — a brand's real checkout or login flow essentially never lives on a free site-builder subdomain.

AI-confirmed evidence

A flagged ad's destination is crawled and passed through the same Claude-Vision-based content classifier used elsewhere in Kansyn, so a finding comes with an actual read of the page — not just "this domain wasn't on your list." When a free-hosting-platform hit is also AI-confirmed as active phishing or brand impersonation, it's raised to critical severity immediately.

From finding to takedown

A flagged ad can be turned directly into a Takedown — carrying the full destination URL (including path), since on a shared host like sites.google.com, the path is what actually identifies the phishing page, not the domain.