All guides

Brand protection

Lookalike domains: what they are and how to find the ones targeting you

Typos, swapped characters, other endings and brand-plus-keyword names. How attackers build lookalike domains, and free ways to check which ones exist for your business.

Updated October 2026 · 6 min read

A lookalike domain is a web address built to be mistaken for yours. Attackers use them for fake sign-in pages, invoice fraud and emails that appear to come from you. They are cheap to register, so a business of any size can be targeted.

The common types

TypeExample (for example.com)Why it works
Typoexampel.com, exmple.comOne wrong or missing letter is easy to miss
Lookalike charactersexamp1e.com, rn instead of mSome characters look almost identical, especially on phones
Other endingsexample.co, example.netPeople remember the name, not the ending
Brand plus keywordexample-login.com, examplesupport.comSounds like an official page for a specific task
Subdomain trickexample.com.secure-login.netThe real domain is at the end, and the start looks right
International charactersLetters from other alphabetsCan look identical to the real name in some fonts

How to check for lookalikes yourself

  1. List the obvious variants.Write down typos, swapped letters, and your name with common endings (.com, .net, .co, .org, your country's ending).
  2. Check which are registered.Look each one up in ICANN's registration lookup. Free open-source tools such as dnstwist can generate and check hundreds of variants at once if you are comfortable with a command line.
  3. Search certificate logs.Websites with HTTPS get certificates that are recorded in public Certificate Transparency logs. Searching those logs for your brand name often finds phishing sites within hours of them going live.
  4. Look at what each one does.A registered name with no website and no mail servers is low risk. One with mail servers, a login page, or your logo needs action now.

Signs a lookalike is dangerous

  • It was registered recently, especially in the last 30 days.
  • It has mail servers (MX records), so it can send email as if it were you.
  • Its website copies your sign-in page, logo or wording.
  • It has a fresh HTTPS certificate, so browsers show the padlock.
  • It redirects to your real site, a trick to look harmless while it is being tested.

Protect yourself before it happens

  • Register your most obvious variants.A handful of key typos and endings costs little compared with a fraud loss.
  • Publish SPF, DKIM and DMARC for your domain.They stop attackers sending email from your real domain, which pushes them toward lookalikes you can spot.
  • Tell staff and customers how you contact them.For example: we never ask you to sign in from an email link, and we never change bank details by email.
  • Check regularly.New lookalikes appear all the time. A one-off check goes stale within weeks.

If you find one being used for phishing, our guide on taking down a phishing domain walks through the reports to make.

General information, not legal advice. Laws, contracts and provider processes change; check the linked sources for current details.

Sign in