Skip to content

Home Topics Email Security Management Lookalike domain spoofing

Email Security Management · Lookalike domain spoofing

How to set up lookalike domain spoofing: step-by-step guide (2026)

Short answer

To set up lookalike domain spoofing: Register the most obvious typo and hyphen variants of your domain; Monitor new registrations that contain your brand string; Configure inbound gateway rules to flag display names matching executives from external domains. Then train finance and executive assistants specifically on this pattern.

DMARC stops exact-domain spoofing, so attackers moved to lookalikes. It is now the dominant brand-impersonation technique.

How to implement lookalike domain spoofing#

  1. Register the most obvious typo and hyphen variants of your domain.
  2. Monitor new registrations that contain your brand string.
  3. Configure inbound gateway rules to flag display names matching executives from external domains.
  4. Train finance and executive assistants specifically on this pattern.

How to verify it worked#

Send a test message to seed mailboxes at Gmail, Outlook, and Yahoo, then inspect the Authentication-Results and delivery headers. Repeat after any DNS or sending-platform change.

Common mistakes#

  • Assuming DMARC p=reject protects against lookalikes.
  • Registering variants but leaving them without DMARC reject themselves.

Frequently asked questions#

How many lookalike domains should I register?

The top 10 to 20 variants by likelihood is a reasonable start; monitoring covers the long tail.

Keep reading on Lookalike domain spoofing