Lookalike Domain
A lookalike domain is a web domain registered to visually imitate a legitimate one — swapped letters, added words, or alternate TLDs — used for phishing, BEC and brand impersonation.
A lookalike domain is a domain registered specifically to be mistaken for a legitimate one: rnicrosoft.com for microsoft.com, acme-invoices.com for acme.com, or the same name under a different ending, like .co or .cam. It is the infrastructure layer beneath a large share of phishing and business email compromise: the attacker owns the domain outright, so email authentication passes and the deception lives entirely in human perception.
How it works
Lookalikes come in a few reliable shapes. Character substitution swaps visually similar glyphs — rn for m, l for i, a Cyrillic а for a Latin a (a homograph attack). Affix padding adds a plausible word: acme-payments.com, acme-hr.net, login-acme.com. TLD swaps keep the name and change the ending. Typosquatting is the closely related variant that targets typing mistakes rather than reading mistakes.
The domain then serves whichever attack is in play: a cloned login portal built from a phishing kit, a mail domain for a fake invoice or vendor bank-change request, or a lure site for malvertising. Because the attacker legitimately controls the domain, SPF, DKIM and DMARC all pass — the message is authentic mail from a fraudulent sender. In BEC cases, a lookalike of a supplier's domain is often registered mid-negotiation, so the thread continues seamlessly with one letter changed in the address.
How to defend
- Register the obvious variants of your primary domain and monitor new registrations resembling it; takedown services and certificate-transparency monitoring catch many lookalikes at setup time.
- Verify out-of-band, not visually. Train staff — especially finance and procurement — to treat any bank-detail change or urgent payment request as unverified until confirmed on a known-good channel, whatever the sender domain looks like. Our BEC defense playbook sets out the full process.
- Practice the perception skill. Reading a domain carefully under time pressure is trainable; phishing simulations using realistic lookalikes build the reflex far better than a slide about
rnversusm.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo