Typosquatting: look-alike domains
DMARC stops someone sending as your domain. It does nothing about a different domain that merely looks like it — and that is where the money actually moves.
Why look-alikes work when DMARC does not
Once your domain is at DMARC p=reject, nobody can send mail claiming to be you. So they stop trying, and register something adjacent instead.
The uncomfortable part: the attacker fully controls that new domain. They can publish flawless SPF, DKIM and DMARC records for it. Their mail authenticates perfectly, passes every technical check, and lands in the inbox. Authentication proves a message came from the domain it claims — it says nothing about whether a human will read that domain correctly.
This is why look-alikes are the natural next move after you harden email, not an unrelated problem. Improving your own posture pushes attackers one character to the left.
The shapes they take
Not all variants are equally convincing, and the difference matters for triage.
- Extension swap. Your exact brand name under another TLD: example.co, example.net, example.io. The most convincing of all, because the name itself is completely correct.
- Character substitution. Glyphs the eye does not separate at reading speed: a lowercase l for an i, rn for m, 0 for O.
- Omission, doubling, transposition. exemple.com, exaample.com, exapmle.com. These catch typing errors rather than reading errors, which makes them weaker for targeted fraud and better for opportunistic traffic capture.
- Combosquatting. Your real name plus a plausible word: example-support.com, example-billing.com, secure-example.com. Nothing is misspelled, which is exactly why it reads as legitimate.
- Homoglyphs. Characters from another script that render identically, such as a Cyrillic а in place of a Latin a. Registered as punycode, they appear in DNS with an xn-- prefix. Modern browsers display the punycode form when scripts are mixed, which blunts the attack in the address bar — but does nothing in a mail client showing a display name.
Extension swaps and combosquatting are the two worth losing sleep over. They are the ones that survive a careful reader.
Separating targeting from coincidence
Generate every permutation of a brand name and you get hundreds of domains, most of them registered by nobody, some by legitimate businesses that happen to share letters with you. Hand that list to a security team and it gets ignored, which is worse than not producing it.
The filter that makes the list actionable rests on two questions.
Could it genuinely be mistaken for yours? Your exact brand name under another extension, or a variant the eye does not catch. A domain sharing four letters with you is not a look-alike, it is a coincidence.
Was it registered after your domain? This is the question that separates a threat from a neighbour, and it is the one most tools skip. A domain registered before yours cannot have been created to imitate you. It may be a competitor, an unrelated company, or a squatter who got there first — none of which is an attack on you.
This is the rule ReconScope applies: only look-alikes that could deceive AND were registered after your own domain count against you. Spelling neighbours predating your brand are listed separately and never affect your score. A mail server on its own is not held against a domain either, since every real business has one.
The point of the filter is not elegance. It is that a list of six domains gets acted on and a list of two hundred does not.
Signs a look-alike is being prepared
A registered domain sitting idle is a possibility. These signals turn it into something with a timeline.
- MX records configured. The domain can receive and send mail. For invoice fraud this is the prerequisite, and its presence on a recently registered look-alike is the strongest single signal you will get.
- A TLS certificate issued. Visible in Certificate Transparency logs, often days before anything is served. Someone is building a site, not parking a name.
- A login page that resembles yours. Credential harvesting, aimed at your customers or your staff.
- Recent registration, short registration period. Fraud infrastructure is rented for months, not a decade.
- Privacy-protected registration paired with all of the above. Common enough to be weak alone, meaningful in company.
Two or more of these together, on a domain that passed the filter above, is worth acting on the same week.
What to do about one
In rough order of speed rather than of formality.
- Report to the registrar. Every registrar has an abuse contact and is obliged to process reports. Include evidence: the fraudulent page, headers of a message sent from the domain, the resemblance to your brand.
- Report to anti-phishing services, Google Safe Browsing first. A flagged domain gets a full-page red warning in Chrome, Firefox and Safari, which cuts its effectiveness faster than any takedown.
- Warn internally. Your finance team is the target for invoice fraud, and they need to know a specific domain is circulating rather than a general reminder to be careful.
- Warn customers if a login page is impersonating you. Unpleasant, and far less unpleasant than the alternative.
- Consider a dispute procedure for a domain that reproduces a registered trademark: UDRP for generic extensions, SYRELI for .fr. Slower and it costs money, so it fits a persistent case rather than a first response.
Keep DMARC at p=reject throughout. It does not stop the look-alike, but it stops the attacker also spoofing your real domain, which would otherwise double their options at no extra cost.
Defensive registration, without buying five hundred domains
The instinct is to register every variant. The arithmetic kills it: hundreds of permutations across dozens of extensions, renewed annually, forever.
Buy where the risk concentrates instead:
- Your exact brand under the extensions that matter for your market. For a French company, .com and .fr at minimum, plus .net and .eu if the budget allows.
- The two or three character substitutions that genuinely deceive at reading speed, which is a much shorter list than a generator produces.
- Combosquatting terms tied to money: your brand plus support, billing, invoice, secure, in your working languages.
Point everything you buy at a redirect to your real site. It costs nothing extra, removes the domain from circulation permanently, and quietly recovers the traffic of anyone who mistyped.
A dozen domains at roughly ten euros a year covers most of the realistic risk. Beyond that you are paying rent on possibilities, and the money is better spent on detection.
Frequently asked questions
Does DMARC protect me from look-alike domains?
No. DMARC governs your domain, and a look-alike is a different domain that the attacker fully controls — they can publish perfect SPF, DKIM and DMARC records for it, so their mail authenticates and is delivered. Keep p=reject anyway: it stops them also spoofing your real domain, which would otherwise give them both options at no extra cost.
Which look-alike domains should I actually worry about?
Those that could genuinely be mistaken for yours and were registered after your own domain. Your exact brand under another extension, or a variant the eye does not catch, are the two shapes that survive a careful reader. A domain registered before yours cannot have been created to imitate you, and a domain sharing a few letters is a coincidence. Without that filter the list runs to hundreds and gets ignored.
Should I register every variation of my domain?
No, the arithmetic does not work — hundreds of permutations across dozens of extensions, renewed forever. Buy where risk concentrates: your exact brand under the extensions that matter for your market, the two or three substitutions that genuinely deceive, and combosquatting terms tied to money such as support, billing or invoice. Around a dozen domains covers most of the realistic risk.
How do I know a look-alike is actively being used?
Look for MX records, which mean the domain can send and receive mail and are the prerequisite for invoice fraud. Then a TLS certificate in Certificate Transparency logs, often issued days before anything is served, a login page resembling yours, and a recent registration for a short period. Two or more of those together, on a domain that could genuinely deceive, is worth acting on the same week.
See where your own domain stands
A free, fully passive scan. Public data only, no intrusion, no account required.
Scan my domain