Lookalike Domain
A Lookalike Domain is a deceptively similar internet or email domain that attackers use to imitate brand identities and abuse trust. Such domains often differ only minimally from the original – for example through swapped letters, similar characters or slightly modified endings.
Common techniques are typosquatting (missing, swapped or doubled letters), homoglyphs (similar-looking characters, partly from other alphabets) and deviating top-level domains. Such domains are used for phishing sites, spoofed sender addresses in BEC campaigns or fraudulent shops. The damage goes beyond technical systems and can directly affect reputation, revenue and customer trust.
Countermeasures combine continuous domain monitoring, defensive registration of obvious variants, takedown processes and email authentication via SPF, DKIM and DMARC. The monitoring frequently relies on Threat Intelligence in order to detect newly registered suspicious domains at an early stage.