Resources · Lookalike domains, Brand impersonation, Attack surface, Phishing
Lookalike domains and typosquatting: finding the ones that impersonate your company
A domain one letter away from yours can host a fake login page or send invoices in your name, and it may belong to a third party, outside the scope of your existing monitoring. How typosquatting works, why DMARC does not stop it, and what to do when you find one.
Typosquatting means registering a misspelled version of another domain to catch people who mistype the address. Other lookalike domains add words, change the ending or use characters that look alike. Together they are the wider family: any address that can be mistaken for a company's own.
Such a domain may belong to a third party and sit outside the scope of your existing monitoring. It matters because of what it can carry: a copy of your login page, an email that looks like it came from your finance team, or a shop that uses your name.
Typosquatting examples: what lookalike domains look like
MITRE ATT&CK, the public catalog of attacker techniques, describes it plainly. Adversaries "may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD)" (T1583.001). For a company whose domain is acmepay.com, that looks like:
- a typo: acmepya.com, acmepay.co;
- an added word: acmepay-billing.com, acmepay-support.com;
- a different ending: acmepay.net, acmepay.shop;
- characters that look alike: "rn" in place of "m", or a letter from another alphabet that looks identical on screen (a homoglyph).
The same word is also used for malicious software packages named after popular ones. This article is about domains.
How lookalike domains are used for brand impersonation
- Fake login pages. A cloned sign-in page on a near-identical address collects employee or customer passwords. Password-stealing malware (infostealers) is another way criminals collect login details.
- Payment and invoice fraud by email. A message from a domain one letter off asks a customer or supplier to pay into a new account. The FBI's advice on business email compromise includes: "Be alert to hyperlinks that may contain misspellings of the actual domain name" (FBI IC3, September 11, 2024). In 2025 the FBI's Internet Crime Complaint Center received 24,768 business email compromise complaints, with about $3.05 billion in reported losses; the report does not say how many used lookalike domains (IC3 2025 report).
- Fake shops and support sites that use your name and logo to sell, collect card details or offer "help".
Not every lookalike domain is hostile: some belong to legitimate businesses with similar names, or to your own company. A domain showing a holding page, or no website at all, can still be used to send email; how it looks does not establish whether it is harmless.
Does DMARC stop lookalike domains?
DMARC is the email standard that lets a domain owner tell receiving servers what to do with messages that fail authentication. It is worth having: with an enforced policy (quarantine or reject), it makes exact-domain spoofing much harder. But its own specification is clear about the limit: DMARC "does not address the use of visually similar domain names or abuse of the RFC5322.From human-readable display name" (RFC 9989). A lookalike domain the attacker controls can pass the SPF, DKIM and DMARC checks for that domain. Those checks confirm that the sender is authorized to use acmepya.com; they say nothing about whether the message can be trusted.
Domain monitoring: what finding a lookalike domain means
Lookalike-domain monitoring tracks similar registrations and changes to the domains already found. The signals available can include registration records, DNS changes, certificates and website content, and coverage varies by service. A result tells you that such a domain exists. It does not tell you what the owner intends, and resemblance alone does not make a domain hostile. Give the list an owner on your side, and sort it by what each domain shows:
- when it was registered, and by whom, if the registration data is public;
- whether it serves a website, and whether that site copies your name, logo or pages;
- whether its public records suggest it is set up for email, although that alone does not show it sends or receives messages;
- whether it is already mentioned in reports from customers or employees.
SeguriScan, IntruForce's attack surface monitoring and data leak detection platform, looks for lookalike domains that may impersonate your company. It also covers the systems your company exposes to the internet and company data found in leaks. Do not treat the results as a complete inventory of lookalike domains. Finding a domain does not remove it from the internet or block access to it. A finding is a reason for someone on your team to check who owns the domain and what it is used for.
What you can do about a lookalike domain
- Ask your IT team to preserve the evidence: the full address, dated screenshots and the original email with its headers. Confirm any request to change bank details through a contact channel you already know, and if money has already been sent, contact your bank at once.
- If it is being used for phishing, warn the people it targets and block the domain in your email and web filters.
- Report the abuse to the registrar and the hosting provider through their abuse contacts; the response depends on the evidence, their obligations and their policies, and suspension is not guaranteed.
- If the domain uses your trademark, consider a formal complaint.
- Consider registering the most relevant variants of your own domain, keeping renewal costs in mind; no company can cover every lookalike.
- Ask your email administrator to deploy DMARC for your own domain, checking legitimate senders and reports before moving to quarantine or rejection, and knowing what it does and does not cover.
For generic endings such as .com, the Uniform Domain-Name Dispute-Resolution Policy (UDRP) offers one route for trademark disputes that meet its conditions (ICANN). The complainant must prove three things:
- the domain is identical or confusingly similar to its trademark;
- the holder has no rights or legitimate interests in it;
- it was registered and is being used in bad faith.
A complaint can end in transfer or cancellation of the domain, but only if the panel accepts it. WIPO handled over 6,200 domain name cases in 2025, its highest caseload on record (WIPO). Country-code domains have their own procedures: WIPO administers disputes for several of them, including .mx, .co, .pe and .es (WIPO ccTLDs); for .ar and .cl, check the procedure of each country's registry.
Want to know which lookalike domains and internet-facing systems show up for your company? Use Check My Company below, or go to the Check My Company page. It is a request to the IntruForce team, answered by email. Nothing that interacts with your systems runs without your confirmation.