Somewhere out there, your business might have an evil twin. Not a competitor, but an impostor: a web domain that looks almost exactly like yours, registered by a criminal to impersonate your business. If your website is yourcompany.com, the evil twin might be yourcompany.co, or yourcompany.net, or yourc0mpany.com with a zero instead of an o, or yourcompany-billing.com. To a busy person glancing at an email, it reads as you. And that is exactly the point, because criminals use these lookalike domains to email your clients, pretending to be you, and to run scams in your name.
This is a threat many business owners have never considered, because it does not attack your systems at all. It attacks your identity, out in the world, using a domain you do not control to fool the people who trust you. It is distinct from the weaknesses in your own website, which we cover in website security; this is about impostor domains impersonating you. The good news is that you can spot these, defend against them cheaply, and protect your clients. Let me show you how.
What a lookalike domain is, and how criminals use it
A lookalike domain is a web address registered to closely resemble a real one, in order to impersonate it. The technique of registering slight misspellings of a domain is often called typosquatting, but the broader idea covers any domain crafted to pass for yours at a glance. Registering a domain is cheap and easy, and nothing stops a criminal from grabbing a near-copy of yours.
Once they have it, they put it to work in a few damaging ways. The most common and costly is email impersonation. Using an address at the lookalike domain, something like billing@yourcompany-invoices.com, the criminal emails your clients, vendors, or partners, posing as your business. Because the domain looks right at a quick read, recipients trust it, and the criminal uses that trust to run invoice fraud, redirect payments, or phish for information, the same family of scams as business email compromise, just launched from a domain that mimics yours rather than a hacked account.
They also build fake websites. A criminal can put up a copy of your site on the lookalike domain to trick your customers into entering information or making payments, or simply to damage your reputation. And plain typosquatting catches people who mistype your web address, sending them to the impostor instead of you. Across all of these, the criminal is borrowing your identity and your customers' trust, using a domain you never owned and may not even know exists.
Why this is so hard to catch
The danger of lookalike domains is that they exploit how little attention we pay to exact web addresses. When an email arrives that looks like it is from a company you know, you rarely scrutinize the domain character by character. A one-letter difference, a swapped extension, an added word, these slip right past a normal glance, especially on a phone. Your clients are not being careless; they are being human, and the scam is engineered to beat exactly that human tendency.
It is also hard for you to catch because it happens outside your own systems. There is no alarm on your end when a criminal registers a lookalike and starts emailing your clients from it. You might only find out when a confused client asks about a strange invoice, or worse, after one of them has been defrauded. That invisibility is what makes proactive defense so valuable.
How to spot a lookalike domain
Knowing the common tricks helps you and your team recognize impostor domains, both to protect yourselves and to check whether anyone is impersonating you. Watch for these patterns.
A different extension is one of the most common: yourcompany.co, .net, .org, or some other ending instead of your real .com. The name looks identical, but it is a completely different domain owned by someone else. Then there are altered letters: a letter added, removed, or swapped, like yourcompany.com becoming yourcompnay.com or yourcompanys.com. Look-alike characters are sneakier, substituting characters that resemble others, such as a zero for the letter o, a capital I for a lowercase l, or the pair "rn" standing in for "m." And added words or hyphens create plausible-looking variants, like yourcompany-support.com, yourcompany-billing.com, or yourcompanyinc.com.
It is worth periodically checking for these variations of your own domain to see whether any have been registered, and there are monitoring tools and services that watch for lookalike registrations of your domain and alert you, which is a genuinely useful safeguard for a business that relies on its name and email.
How to beat them
Here is the encouraging part: defending against lookalike domains is very doable, and some of it costs only a few dollars. A layered approach protects you and your clients.
Register the obvious defensive variants yourself. This is cheap and effective. Buy the most likely lookalikes and common extensions of your domain, the .co and .net versions, the obvious misspellings, the plausible hyphenated variants, so that a criminal cannot. Domains cost only a few dollars a year each, which makes owning your most impersonatable variants inexpensive insurance against exactly this scam. You do not need to buy hundreds; grabbing the handful most likely to be abused covers most of the risk.
Strengthen your real domain's email so it is harder to spoof. There are standard email authentication settings, with technical names like SPF, DKIM, and DMARC, that help prove your emails genuinely come from your domain and make it harder for criminals to impersonate your actual address, while also helping lookalike and spoofed messages get filtered out. This is a bit technical and is worth setting up with help, and it works hand in hand with the protections we describe in email security.
Monitor for lookalikes, using the periodic checks or a monitoring service mentioned above, so you learn quickly if an impostor domain appears.
Warn your clients proactively, which is one of the most protective things you can do. Let your clients and vendors know your true domain and email address, and remind them, as a standing policy, that you will never change payment or banking details by email and that they should verify any such request by phone. When your clients know your real domain and know to verify money requests, a lookalike email loses most of its power, because even a convincing impostor cannot survive a verification call. This is the same verify-first habit that defeats so many scams, extended to protect the people who trust you.
And if you discover a malicious lookalike actively being used against you, report it, to the domain registrar, and to platforms like Google if a fake site is involved, and warn your clients directly so they are not caught by it.
How we think about it
Protecting your business's identity out in the world, not just your own systems, is part of how we think about security at Red Door Shield, through a simple framework we call KIT: Keep, Inspect, Trust. Keep what is valuable secure, including your domain and email identity, strengthened so it is harder to impersonate, and your key lookalike variants owned by you rather than a criminal. Inspect what is out there, watching for impostor domains that mimic yours. And trust through validation, the verify-first habit, shared with your clients, that makes a lookalike email fail even when it fools the eye. We help businesses protect their whole identity, including the domain and email that so much trust flows through, so an evil twin cannot use it against you.
What ready looks like
Picture your business's identity protected: your real domain's email strengthened against spoofing, the obvious lookalike variants registered and owned by you, a watch in place for new impostor domains, and your clients aware of your true domain and armed with the habit of verifying any payment request. A criminal who registers a near-copy of your domain and emails your clients finds that your clients know your real address, know to verify, and are not fooled, and that the most tempting variants were already taken by you. The evil twin has nothing to work with.
That is what ready feels like against lookalike domains. Not hoping no one impersonates your good name, but protecting your identity and preparing your clients so an impostor domain simply cannot cash in on your reputation.
Lookalike domains are a quiet, clever way for criminals to turn your own good name against your clients, and most businesses never see it coming. But for a few dollars and a little awareness, you can own your most abusable variants, harden your email, watch for impostors, and prepare your clients, and the evil twin loses its power. If you want help protecting your domain, your email, and your business's identity, our free Business Security Assessment is the place to start, and it is a conversation worth having today.
Not sure where your business actually stands?
Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.
Get My Free Security Assessment

