Someone forwards you an email and asks if it is really from you. The logo is right. The signature block is right. The tone is close enough that nobody stopped to think. Then you look at the sender address and notice it is not quite your domain. One letter is off. Maybe an “r” and an “n” sit next to each other where an “m” should be. Maybe “.co” replaced “.com.” Your client already replied to it two days ago.

This is the domain lookalike problem, and it is one of the odder situations a small business can land in, because nothing of yours has actually been broken into. Your email is fine. Your servers are fine. Somebody bought a domain name that resembles yours for the price of a sandwich and pointed it at the people who trust you. The damage lands on your reputation and your client relationships rather than on your network, and most of the security tools a business already pays for were never designed to catch it.

How One Character Fools a Careful Person

People do not read domain names. They recognize them. Your brain sees a familiar shape in the sender field, matches it against what it expects, and moves on to the message. That shortcut is useful ten thousand times a day and harmful exactly once. The variations attackers pick are chosen to survive a glance.

  • Character swaps that look identical at small sizes. A lowercase “l” standing in for a capital “I,” a zero for the letter “O,” or the classic “rn” pair impersonating an “m.”
  • Added or dropped letters. A doubled consonant, a missing vowel, or a shortened version of your name you might plausibly have registered yourself.
  • A different ending. Your name with .net, .co, .biz, .us, or one of the hundreds of newer endings instead of the .com you own.
  • Hyphens added or removed. If your domain runs words together, someone registers the hyphenated version, and the reverse.
  • Your name buried in a longer address. Something like yourcompany.secure-billing-portal.com. People scan left to right, spot what they recognize, and stop reading.

The Federal Trade Commission named this behavior directly when it adopted its Government and Business Impersonation Rule in 2024. Among the deceptive techniques the FTC called out are fraudulently using corporate logos and spoofing email addresses through misspellings or lookalike web addresses. When a federal regulator writes your problem into a rule, you can stop wondering whether it is common.

Why It Is Your Problem Even When Nothing Was Breached

Here is the uncomfortable part. If a client wires money to a fake account because of an email that appeared to come from you, their first thought is not “an unrelated criminal registered a similar domain.” It is “my vendor got hacked.” You will spend weeks explaining a technical distinction to people who are upset about money, and some will not be persuaded.

That is why we treat this as a reputation issue with a technical component rather than a purely technical issue. It sits alongside the broader trend we wrote about in our look at why phishing remains so hard to block, and it fits the pattern we described in what the Stryker cyberattack tells us about the threats facing every business: the attack does not have to touch your systems to cost you.

Find Out What Already Exists

Before you spend a dollar defending against this, spend an hour looking. Most businesses have never checked, and the answer is usually less alarming than they fear. Sometimes the near-miss domain belongs to a legitimate company in another state. Sometimes it belongs to a speculator waiting for an offer.

  1. Write down your exact domain first. Sounds obvious. It is not, because many businesses own three or four domains and use two of them inconsistently.
  2. List twenty to thirty plausible variants by hand. Swaps, drops, additions, hyphens, and the common alternate endings. Twenty minutes and a legal pad is enough.
  3. Check which ones are registered. A public registration lookup tells you whether each is taken and roughly when it was created. Recent creation dates deserve a closer look.
  4. Check what each registered one actually does. Does it load a site? Redirect somewhere? Is it configured to send email? A domain set up to send mail is a different level of concern than a parked page.
  5. Save the results where you will find them again. A dated spreadsheet is the whole system. Next year’s check only helps if you can compare it to this year’s.

Register the Obvious Variants and Watch for New Ones

Defensive registration is real advice with an honest caveat: you cannot buy your way out of this. The number of possible lookalikes is effectively unlimited, and vendors selling portfolios of two hundred defensive domains are selling you a feeling. Buy the handful a normal person would actually mistype, and stop.

Once you own them, do two things. Point them at your real website so a mistyped address still lands correctly, and configure them so they cannot send email. The 2023 joint phishing guidance from CISA, the NSA, the FBI, and the MS-ISAC recommends that organizations set DMARC to reject, and explains that DMARC, working with SPF and DKIM, verifies the sending server of received email by checking published rules. That advice applies to the domains you park just as much as the one you use every day.

For the ones you do not buy, monitoring is the answer. Repeat your manual check once or twice a year, and set a calendar reminder rather than trusting yourself to remember. Commercial monitoring services are worth the money for businesses whose name shows up in payment instructions, but a disciplined annual review beats a subscription nobody reads the alerts from.

Warn People, Then Act on What You Find

The most effective control here is not technical. It is telling your clients, in plain language and more than once, how you actually communicate. Put it in your onboarding packet, your invoice footer, and on your website. Your banking details never change by email. Invoices come from one specific domain. You will never ask for a password. The 2023 CISA guidance recommends regularly educating users on identifying suspicious emails and links and reporting them, and that advice works pointed outward at customers as well as inward at staff.

When you do find a domain impersonating you, work the list calmly. Capture evidence first: screenshots, full email headers, and the exact web address, saved with the date. Then report it to the registrar and the hosting provider, both of which typically publish an abuse contact. Report the impersonation to the FTC at reportfraud.ftc.gov, which the agency identifies as its reporting channel. Tell your clients directly, because a short, unembarrassed heads up from you beats a rumor. And if the domain is trading on your brand name, talk to an attorney, since trademark rights and the FTC’s 2024 impersonation rule, which allows the agency to seek consumer redress and civil penalties, may both be relevant.

The Bottom Line

Lookalike domains exploit the gap between what your systems protect and what your customers assume. You cannot patch an assumption, but you can shrink it. Know which near-miss domains exist, own the few that matter, lock down the ones you park so they cannot send mail, check again on a schedule, and tell your clients plainly how you communicate. That is an afternoon of work and a recurring calendar entry.

If you are not sure what similar domains are out there, or you have already found one and want help handling it without overreacting, we are happy to walk through it with you. We do this work for small and mid-sized businesses across Denton County, and the first conversation is usually short. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).