undoppel

Brand protection guide

Lookalike Domains and Phishing: Why They Work and How to Stop Them

**Lookalike domains** are web addresses deliberately registered to resemble a legitimate brand's domain so victims mistake them for the real thing…

Lookalike domains are web addresses deliberately registered to resemble a legitimate brand's domain so victims mistake them for the real thing. Attackers use them to send convincing phishing emails, host fake login pages, and intercept payments — and they work because the human eye skims domains instead of reading them character by character.

What a lookalike domain actually is

A lookalike domain (also called an impersonation domain or spoofed domain) is any registration crafted to be visually or cognitively confused with a target. The goal is to borrow trust the real brand has already earned. If a customer trusts `example.com`, they'll extend that trust to `examp1e.com` or `example-support.com` without a second thought — which is exactly the reaction attackers engineer.

These domains rarely exist for their own sake. They are infrastructure for a larger attack: a phishing campaign, business email compromise, credential harvesting, or fake e-commerce storefronts that take money and deliver nothing.

The main types of lookalike domains

Attackers have a well-worn toolkit. Recognizing the categories helps you predict what to defend against.

Why lookalike domains succeed

The attack exploits how people read, not a flaw in any software. Three mechanisms do most of the work.

Recognition beats verification. The brain pattern-matches a familiar word rather than parsing each character. Under time pressure — an urgent email, a payment deadline — nobody audits a URL letter by letter.

Truncation and trust cues hide the truth. Email clients and mobile browsers shorten displayed addresses. A long combosquatted or subdomain-based URL often shows only the part the attacker wants you to see. Add a padlock icon and the illusion is complete.

A valid TLS certificate looks legitimate. Free certificates are trivial to obtain for any domain an attacker controls. The padlock proves the connection is encrypted — not that the site is who it claims to be. Many users conflate the two, and attackers rely on that confusion.

Email authentication gaps. If your real domain hasn't published strong SPF, DKIM, and DMARC records, attackers can spoof it directly. But even with those in place, a lookalike domain is a separate registration the attacker fully controls, so it can pass its own authentication checks and sail past basic filters.

How lookalike domains fuel phishing

Once a lookalike is registered, the attacker assembles the rest of the machine:

  1. MX records get configured so the domain can send and receive email — enabling phishing that appears to come from your company or that targets your staff and vendors.
  2. A TLS certificate is issued, giving the fake site a padlock and an `https://` address.
  3. A cloned login or checkout page is deployed, often a pixel-perfect copy of your real site pulled straight from your public HTML.
  4. The campaign launches — emails, SMS, ads, or malicious links — driving victims to the lookalike to enter credentials, card numbers, or approve fraudulent payments.

The credentials or payments captured then feed account takeover, wire fraud, or resale on criminal markets. A single convincing lookalike domain can power thousands of individual attacks.

How to spot a lookalike domain

Train yourself and your team to slow down and check the parts that matter.

The problem: your customers won't do any of this reliably, and neither will busy employees. Manual vigilance doesn't scale — you can't ask every user to audit every URL. That's why the real defense is finding these domains before they're used against you.

How to stop lookalike domains

Prevention runs on two tracks: harden what you own, and detect what attackers register.

Lock down your own domain.

Detect the ones you can't pre-register. You cannot buy every permutation — the combinatorial space of homoglyphs, combosquats, and TLDs is effectively infinite. What you can do is watch for registrations as they happen. This is where undoppel.io does the work for you: it generates the full range of typo, homoglyph, TLD-swap, and combosquat permutations of your domain, then checks which ones actually exist — resolving DNS, inspecting MX records to see which are mail-ready, reading WHOIS registration details, and watching certificate transparency logs for freshly issued TLS certs on lookalike names.

Those signals matter because they tell you not just that a lookalike exists, but how far along it is. A newly registered domain with MX records live and a TLS certificate issued is a domain being armed for phishing — the window to act is now, before the campaign launches. Catching it at registration, rather than after your customers report a scam, is the difference between a takedown and a breach.

What to do next

Find out which lookalike domains already target your brand. Run a free scan at undoppel.io — enter your domain and see the typosquats, homoglyphs, combosquats, and TLD variants that exist right now, which ones are configured to send email, and which have certificates suggesting an active phishing setup. Start there, then prioritize takedowns and defensive registrations based on what's actually live rather than guessing.

Is your brand being impersonated?

Run a free instant scan for typosquats and lookalike domains targeting your brand.

Run a free brand scan →