# Look-alike MCP namespaces and brand risk

Why a verified domain is not the same as vendor affiliation.

## The trap
Anyone can register a domain that looks like a brand, publish an MCP server under that namespace, and collect installs from people who skim.

## What domain verification proves
Control of *that* domain — not permission from the brand.

## What we do
Scoring v3.2 corroboration caps and impersonation checks reduce “identity-only” high scores. Official rules stay farm-safe. See [methodology](/methodology).

## What you should do
Prefer Official for brand names. Open the publisher and namespace. If the card says look-alike caution, treat it as a hard stop until proven otherwise.
