Skip to content

Slack app

The Have I Been Squatted app brings adversarial infrastructure investigation into Slack. Mention @Have I Been Squatted in a channel or send it a direct message, and it answers in the thread with your own Have I Been Squatted access.

Add to Slack

Installing the app gives nobody access to your Have I Been Squatted data. Each person links their own account the first time they ask, and the app works only with that person’s access.

  • Analyze a domain: DNS, mail, registration, hosting, HTTP, classification and a verdict, for any domain or hostname from an alert or ticket.
  • Hunt lookalikes: scan a domain for registered typosquats, or find unregistered lookalikes you could register defensively. Scans run in the background, and the app posts the results in the thread when they finish.
  • Search certificate transparency for new certificates imitating your domains.
  • Query your detections: ask about lookalike results for your monitored domains, and Email Intelligence or Site Canary events with those add-ons.
  • Triage results: tag a result as owned, ignored, false positive or malicious.
  • Work with detection rules: read your rules, and draft, edit, enable, disable or delete them.

Monitored domain management, alert triage, takedowns and response dispatch are available through the MCP server.

  1. Select Add to Slack above, or open agent.haveibeensquatted.com/channels/slack/install.

  2. Choose the workspace, review the permissions the app requests, and select Allow. Depending on your workspace settings, a Slack admin may need to approve the app first. On Enterprise Grid, an org admin can install the app for the whole organization.

  3. The confirmation page names the workspace. Open Slack and mention @Have I Been Squatted in a channel, or send it a direct message from the app’s Messages tab. To use it in a channel, invite the app to that channel first.

  4. The first time you ask, the app sends you a private Connect Have I Been Squatted prompt. The link is for you only, works once and expires after 10 minutes.

  5. Sign in with your Have I Been Squatted account, choose the organization to connect, and approve the connection. The confirmation page shows the organization and your role. Return to Slack and ask again.

Every person in the workspace links their own account. The app never shares one person’s access with another.

  • In a channel, mention the app. It answers in the message’s thread. Mention it again in the thread to follow up.
  • In a direct message, every message is part of one ongoing conversation, answered at the top level. A reply inside a thread in the DM starts its own conversation.
  • Ask in plain language, for example:
    • @Have I Been Squatted analyze login.example.com
    • @Have I Been Squatted what new lookalikes of example.com appeared this week?
    • @Have I Been Squatted run a typosquat scan of example.com
    • @Have I Been Squatted search certificate transparency for examp1e

The app reacts to your message to show progress:

Reaction Meaning
👀 The app picked up your message.
✅ The app posted its first reply: an answer, an approval request, a scan notice or a command reply.
⚠️ The request failed after retries. The app tells you it could not answer.

Send these words on their own, as a mention or a direct message:

Command Action
help Shows what the app can do.
connect Sends a new link to connect your Have I Been Squatted account. Also link or login.
disconnect Removes your link, and deletes your stored access and your conversations with the app. Also unlink or logout.

The app never changes your data on its own. Before it tags a result or creates, updates, enables, disables or deletes a rule, it posts the exact change with Approve and Deny buttons.

  • Only the person who asked can approve or deny.
  • Rule changes are shown as the exact arguments that will be sent.
  • An approved change runs once, with the access you had when you asked.
  • A request expires after one hour without a decision. Nothing is changed.
  • Changes also need an organization admin. If you are not an admin, the change is refused.

Scans of a domain you typed in your message run immediately. A scan of any other domain, such as one the app found in a result, also asks for your approval first.

The app reads only messages addressed to it: mentions of the app in channels it was invited to, and direct messages to the app. It never reads channel history or other messages.

Permission Why the app needs it
app_mentions:read Answer when someone mentions the app in a channel.
im:history Answer direct messages to the app. The app receives only messages in its own DMs.
chat:write Post answers, approval requests and connect prompts.
reactions:write Mark a message as being worked on, answered or failed.
mcp:connect Let Slackbot use the Have I Been Squatted MCP server.

What the app stores, and for how long:

  • The workspace’s installation, including the app’s bot token, until the app is uninstalled.
  • Each linked person’s Have I Been Squatted access, until they send disconnect or the app is uninstalled.
  • Conversations with the app, deleted one week after the last message.
  • Approval requests, deleted at most 25 hours after they are made.
  • Slack event IDs, kept for two hours to avoid answering twice.

Tokens are encrypted at rest and bound to the person or workspace they belong to. They are never sent to the model, logged or shown in Slack.

Messages you send the app are processed by Anthropic’s Claude models through Cloudflare, without caching or logging there. The app calls Have I Been Squatted with your own access, so every call is limited to your organization and role, and is recorded with the user, the organization and the arguments.

A Slack admin can remove the app from the workspace’s app management settings. Uninstalling the app, or revoking its token, deletes the installation and all of its data for every workspace it served: linked access, conversations, approval requests and pending sign-ins. If the app is installed again, everyone links their account again.

To remove only your own link and data, send disconnect to the app.

The app also connects Slackbot to the Have I Been Squatted MCP server. Where your workspace has Slackbot’s AI features, Slackbot can call the Have I Been Squatted tools. It asks you to sign in with your Have I Been Squatted account and choose an organization the first time.

  • A Have I Been Squatted account in an organization. Sign up if you do not have one.
  • Lookups (analyze, scans and certificate transparency search) work on every plan. Your monitoring data and detection rules need a Pro, Business or Enterprise plan. Email Intelligence and Site Canary data need those add-ons. See pricing.
  • Tagging results and changing rules needs an organization admin.

The app limits how many scans each person can start, and how many requests each workspace can make, per hour.

Contact us at haveibeensquatted.com/contact or support@haveibeensquatted.com. See the privacy policy and terms.