What lookalike domain spoofing is#
Lookalike (cousin) domain spoofing uses a domain visually similar to yours (examp1e.com, example-billing.com) to send mail that passes authentication for the attacker's domain while impersonating your brand.
Why it matters#
DMARC stops exact-domain spoofing, so attackers moved to lookalikes. It is now the dominant brand-impersonation technique.
How mailbox providers use it#
Gmail, Microsoft, and Yahoo combine authentication results, sender reputation, and recipient engagement into a placement decision made per message. Lookalike domain spoofing feeds directly into that model, and weaknesses compound with other signals.
How to measure the impact#
- Baseline inbox placement with seed tests before any change.
- Make one change at a time and hold volume steady.
- Re-test after 48 to 72 hours; provider models need time to update.
- Track Postmaster Tools and SNDS alongside your seed results.
Improving it#
- Register the most obvious typo and hyphen variants of your domain.
- Monitor new registrations that contain your brand string.
- Configure inbound gateway rules to flag display names matching executives from external domains.
- Train finance and executive assistants specifically on this pattern.
Frequently asked questions#
How many lookalike domains should I register?
The top 10 to 20 variants by likelihood is a reasonable start; monitoring covers the long tail.