phantomstrike.io

Learn

Brand and domain abuse

Lookalike domains: how to find and stop domain impersonation

Updated September 15, 2026 · 5 min read

Anyone can register a domain that looks almost identical to yours. acrne.com instead of acme.com, or acme-login.com, or acme.co instead of acme.com. Attackers use these lookalike domains to send phishing and fake invoices that pass a quick glance, because the name is nearly right. Finding them early is the difference between a blocked attempt and a paid fraudulent invoice.

How lookalike domains are built

Attackers generate variations of a target brand using a few reliable techniques:

Why the mail records matter most

A registered lookalike domain is a nuisance. A registered lookalike domain with mail records is a live threat, because it can send email. When you find lookalikes, the ones that publish MX records are the ones to act on first: they are set up to send, and sending is how impersonation reaches your customers and staff.

What you can do

  1. Find them. Check the common variations of your name regularly, not once. New ones get registered all the time.
  2. Prioritise by mail capability. A lookalike with MX records can send phishing today; treat it as urgent.
  3. Block them. Add the confirmed bad domains to your mail gateway and DNS filter so your own people never reach them or receive from them.
  4. Warn your people. A short note to staff and, where appropriate, customers about the specific names in use is cheap and effective.
  5. Report the worst. A domain actively hosting a phishing copy of your site can be reported to its registrar's abuse contact and to Google Safe Browsing.
  6. Consider defensive registration. For the closest and most dangerous variants, registering them yourself takes them off the board.

You cannot block what you have not found. The hard part of lookalike domains is not the response, it is noticing they exist before they are used.

Automating the hard part

PhantomStrike checks a few hundred variants of your brand on every scan and flags the ones registered by other people, marking which publish mail records. On paid plans it watches for new ones continuously, gives you a blocklist feed your filters pull automatically, and generates a takedown report addressed to the registrar. Start with a free scan to see what already exists around your name.

See your domain the way an attacker does

Run a free scan for your exposure score and the exact records that fix each finding. No account, and we never touch your systems.

Scan your domain free

Common questions

Is registering a lookalike of my domain illegal?

Registration alone often is not, but using one to impersonate you, host phishing, or trade on your brand can be, and is grounds for a takedown with the registrar and, for trademarks, a UDRP complaint.

Should I buy every lookalike of my domain?

No, there are too many. Register the closest and most convincing variants defensively, and monitor for the rest so you can act when one is actually set up to send mail or host a fake site.

How do I get a phishing lookalike taken down?

Report it to the domain's registrar abuse contact with evidence, and submit it to Google Safe Browsing so browsers warn visitors. A takedown report addressed to the registrar is the fastest first step.