Brand and domain abuse
Lookalike domains: how to find and stop domain impersonation
Updated September 15, 2026 · 5 min read
Anyone can register a domain that looks almost identical to yours. acrne.com instead of acme.com, or acme-login.com, or acme.co instead of acme.com. Attackers use these lookalike domains to send phishing and fake invoices that pass a quick glance, because the name is nearly right. Finding them early is the difference between a blocked attempt and a paid fraudulent invoice.
How lookalike domains are built
Attackers generate variations of a target brand using a few reliable techniques:
- Homoglyphs: swapping letters that look alike, such as rn for m, or a zero for the letter o.
- Typos: doubled or dropped letters that a person types by mistake, like acmee.com.
- Different top-level domains: the same name under .co, .net, .io, or a country code instead of your .com.
- Added words: acme-support.com or acme-billing.com, which read as an official section of your site.
Why the mail records matter most
A registered lookalike domain is a nuisance. A registered lookalike domain with mail records is a live threat, because it can send email. When you find lookalikes, the ones that publish MX records are the ones to act on first: they are set up to send, and sending is how impersonation reaches your customers and staff.
What you can do
- Find them. Check the common variations of your name regularly, not once. New ones get registered all the time.
- Prioritise by mail capability. A lookalike with MX records can send phishing today; treat it as urgent.
- Block them. Add the confirmed bad domains to your mail gateway and DNS filter so your own people never reach them or receive from them.
- Warn your people. A short note to staff and, where appropriate, customers about the specific names in use is cheap and effective.
- Report the worst. A domain actively hosting a phishing copy of your site can be reported to its registrar's abuse contact and to Google Safe Browsing.
- Consider defensive registration. For the closest and most dangerous variants, registering them yourself takes them off the board.
You cannot block what you have not found. The hard part of lookalike domains is not the response, it is noticing they exist before they are used.
Automating the hard part
PhantomStrike checks a few hundred variants of your brand on every scan and flags the ones registered by other people, marking which publish mail records. On paid plans it watches for new ones continuously, gives you a blocklist feed your filters pull automatically, and generates a takedown report addressed to the registrar. Start with a free scan to see what already exists around your name.
See your domain the way an attacker does
Run a free scan for your exposure score and the exact records that fix each finding. No account, and we never touch your systems.
Scan your domain freeCommon questions
Is registering a lookalike of my domain illegal?
Registration alone often is not, but using one to impersonate you, host phishing, or trade on your brand can be, and is grounds for a takedown with the registrar and, for trademarks, a UDRP complaint.
Should I buy every lookalike of my domain?
No, there are too many. Register the closest and most convincing variants defensively, and monitor for the rest so you can act when one is actually set up to send mail or host a fake site.
How do I get a phishing lookalike taken down?
Report it to the domain's registrar abuse contact with evidence, and submit it to Google Safe Browsing so browsers warn visitors. A takedown report addressed to the registrar is the fastest first step.