Module 2 of 4
Lookalike Domains and Typosquatting
A lookalike domain is one registered specifically to be confused with a real one – not spoofed, but a genuinely different, separately-registered domain with its own valid DNS, its own valid SPF/DKIM/DMARC, sending real mail that just happens to be built to deceive.
The common substitution patterns
- Omission: dropping a letter (
exmple.com) - Insertion: adding one (
examplle.com) - Transposition: swapping adjacent letters (
examlpe.com) - Adjacent-keyboard substitution: a typo a real user might actually make (
ecample.com) - Homoglyphs: visually near-identical characters (a lowercase
lfor anI, a zero for anO,rnrendered to look likem) - Hyphenation / TLD swaps:
example-inc.com, or the same name on a different top-level domain
Why enforcement doesn't touch this
This is the detail worth sitting with: everything in Courses 1 and 2 – SPF, DKIM, DMARC enforcement, even a perfect p=reject rollout – protects your own domain from being impersonated directly. None of it has any authority over a domain someone else registers. examp1e.com is a completely separate domain from example.com, free to publish its own perfectly valid SPF and DKIM and DMARC, because as far as DNS and email authentication are concerned, it's telling the truth about being exactly what it is.
What actually helps
- Proactive monitoring – checking which plausible variants of a domain are already registered, before an attacker uses one. ActiScan's lookalike domain checker generates a bounded set of the substitution patterns above and checks which are live via DNS.
- Employee awareness – the second-most-effective control here is a person pausing on an unexpected payment-change request long enough to check the sending domain character by character.
- Defensive registration – registering the most obvious variants yourself, where that's practical, so an attacker can't.
Try it yourself: Lookalike Domain Checker