← All terms

Lookalike Domain

A lookalike domain is a web domain registered to visually imitate a legitimate one — swapped letters, added words, or alternate TLDs — used for phishing, BEC and brand impersonation.

A lookalike domain is a domain registered specifically to be mistaken for a legitimate one: rnicrosoft.com for microsoft.com, acme-invoices.com for acme.com, or the same name under a different ending, like .co or .cam. It is the infrastructure layer beneath a large share of phishing and business email compromise: the attacker owns the domain outright, so email authentication passes and the deception lives entirely in human perception.

How it works

Lookalikes come in a few reliable shapes. Character substitution swaps visually similar glyphs — rn for m, l for i, a Cyrillic а for a Latin a (a homograph attack). Affix padding adds a plausible word: acme-payments.com, acme-hr.net, login-acme.com. TLD swaps keep the name and change the ending. Typosquatting is the closely related variant that targets typing mistakes rather than reading mistakes.

The domain then serves whichever attack is in play: a cloned login portal built from a phishing kit, a mail domain for a fake invoice or vendor bank-change request, or a lure site for malvertising. Because the attacker legitimately controls the domain, SPF, DKIM and DMARC all pass — the message is authentic mail from a fraudulent sender. In BEC cases, a lookalike of a supplier's domain is often registered mid-negotiation, so the thread continues seamlessly with one letter changed in the address.

How to defend

  • Register the obvious variants of your primary domain and monitor new registrations resembling it; takedown services and certificate-transparency monitoring catch many lookalikes at setup time.
  • Verify out-of-band, not visually. Train staff — especially finance and procurement — to treat any bank-detail change or urgent payment request as unverified until confirmed on a known-good channel, whatever the sender domain looks like. Our BEC defense playbook sets out the full process.
  • Practice the perception skill. Reading a domain carefully under time pressure is trainable; phishing simulations using realistic lookalikes build the reflex far better than a slide about rn versus m.

Related terms

TyposquattingTyposquatting registers look-alike domains — misspellings or swapped characters — to catch mistyped URLs and lend fake emails and sites credibility.SpoofingSpoofing is the falsification of an identity signal — sender address, caller ID, domain, or website — to make an attack appear to come from a trusted source.Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.Phishing KitA phishing kit is a ready-made package of fake login pages, scripts and evasion tools that lets low-skill attackers run professional phishing campaigns.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo