ActiScan
← The Email Threat Landscape

Module 2 of 4

Lookalike Domains and Typosquatting

A lookalike domain is one registered specifically to be confused with a real one – not spoofed, but a genuinely different, separately-registered domain with its own valid DNS, its own valid SPF/DKIM/DMARC, sending real mail that just happens to be built to deceive.

The common substitution patterns

  • Omission: dropping a letter (exmple.com)
  • Insertion: adding one (examplle.com)
  • Transposition: swapping adjacent letters (examlpe.com)
  • Adjacent-keyboard substitution: a typo a real user might actually make (ecample.com)
  • Homoglyphs: visually near-identical characters (a lowercase l for an I, a zero for an O, rn rendered to look like m)
  • Hyphenation / TLD swaps: example-inc.com, or the same name on a different top-level domain

Why enforcement doesn't touch this

This is the detail worth sitting with: everything in Courses 1 and 2 – SPF, DKIM, DMARC enforcement, even a perfect p=reject rollout – protects your own domain from being impersonated directly. None of it has any authority over a domain someone else registers. examp1e.com is a completely separate domain from example.com, free to publish its own perfectly valid SPF and DKIM and DMARC, because as far as DNS and email authentication are concerned, it's telling the truth about being exactly what it is.

What actually helps

  • Proactive monitoring – checking which plausible variants of a domain are already registered, before an attacker uses one. ActiScan's lookalike domain checker generates a bounded set of the substitution patterns above and checks which are live via DNS.
  • Employee awareness – the second-most-effective control here is a person pausing on an unexpected payment-change request long enough to check the sending domain character by character.
  • Defensive registration – registering the most obvious variants yourself, where that's practical, so an attacker can't.

Try it yourself: Lookalike Domain Checker