
A lookalike domain is a web address registered to pass for yours at a glance: netsysgr0up.com, netsys-group.com, netsysgroup.co. Scammers use one to email your clients and vendors as you, and your SPF, DKIM and DMARC records can't stop it, because the fake domain isn't yours.
The fix is a mix of email filtering, a few cheap domain purchases, and one rule about payments that nobody gets to skip.
What is a lookalike domain attack?
A lookalike domain attack is a phishing or fraud campaign sent from a domain built to resemble a real company's. The attacker registers it, sets up working email (often with valid authentication records of its own), then writes to people who already trust that company. The goal is almost always money: a changed bank account, a paid invoice, a wire.
The common patterns:
- Character swaps. A zero for an "o," "rn" for "m," a capital "I" for a lowercase "l."
- Added words or hyphens. yourfirm-billing.com, yourfirm-inc.com.
- Different endings. .co, .net or .biz in place of .com.
- Typos. One letter dropped or doubled, the kind of mistake a busy reader's eye fixes on its own.
Why doesn't DMARC stop it?
DMARC protects your exact domain. That's it.
If someone sends mail pretending to be from yourfirm.com, a strict DMARC policy tells receiving servers to reject it. But yourfirm-billing.com is a different domain with its own owner. That owner can publish perfectly valid SPF and DMARC records, and the mail passes every check.
Microsoft says as much in its own documentation: an impersonated domain "might otherwise be considered legitimate (the domain is registered, email authentication DNS records are configured, etc.), except the intent of the domain is to deceive recipients" (Microsoft Learn).
So you still need DMARC. It just covers a different attack.
How much money is this costing businesses?
The FBI's 2025 Internet Crime Report logged 24,768 business email compromise complaints with reported losses of $3,046,598,558 (FBI IC3 2025 Annual Report).
Not every one of those started with a lookalike domain. Some came from hijacked mailboxes, which is a separate problem we cover in our guide to business email compromise. But a lookalike domain is the cheapest way in: no hacking required, just a registration fee and a convincing email thread.
How does the attack usually play out?
It rarely starts with a cold email. The attacker usually knows who you bill and who bills you.
- Research. They read your website, LinkedIn and any leaked email thread they can find.
- Registration. They buy a domain one character away from yours, or from a vendor of yours.
- The hijacked thread. They reply to a real conversation from the lookalike address, so the history looks familiar.
- The ask. "Our bank changed. Please update the account on file before Friday's payment."
The second variation targets your staff instead. Your bookkeeper gets an email that looks like it came from your owner, from yourfirm.co, asking for an urgent wire or gift cards.
How do you spot a lookalike domain?
Read the full sender address, not the display name. The display name says whatever the attacker typed.
- Hover over or tap the sender to see the actual address.
- Read the domain one character at a time, right to left. The eye skims left to right and fills in what it expects.
- Be suspicious of any new request about money or bank details, even inside an old thread.
- Watch for a "Reply-To" address that differs from the "From" address.
Training helps. It won't be enough on its own, because a tired person will eventually miss one character.
How do you protect your business from lookalike domains?
Layer it. No single control covers every case.
1. Turn on impersonation protection in Microsoft 365
Microsoft Defender for Office 365 includes domain and user impersonation protection. Microsoft states it "looks for domains that are similar," checking other endings and slight spelling changes, and you can protect up to 350 named users per anti-phishing policy (Microsoft Learn).
Defender for Office 365 Plan 1 is included in Microsoft 365 Business Premium (Microsoft Learn). If you're paying for Business Premium, you likely own this already. Owning it and configuring it are different things: add your own domains, your leadership team and your key vendors' domains to the policy.
2. Tag external email
Turn on the external sender tag so every message from outside your organization is labeled. A note from "the owner" carrying an External tag is an instant red flag.
3. Buy the obvious lookalikes
Register the .com, .net and .co versions of your domain and the one or two most obvious typos, and point them at your website. It's cheap and removes the easiest options.
You can't buy every variation, so don't try.
4. Monitor for new registrations
Domain monitoring services alert you when someone registers a name close to yours. When one shows up, you can block it in your mail filter before the first email lands, and ask the registrar to take it down if it's being used for fraud.
5. Make payment changes impossible by email alone
This is the control that saves the money. Any request to change bank details, or to send a wire, gets verified by phone using a number you already have on file. Never the number in the email.
Put it in writing. Tell your clients you'll never change payment instructions by email, and ask your vendors to commit to the same.
6. Lock down your real domain too
Publish DMARC at enforcement on your own domain so attackers can't spoof it outright. That pushes them toward lookalikes, which your filtering is now set up to catch. Our DMARC implementation service handles that rollout without breaking legitimate mail.
What should you do if a client already got fooled?
Call your bank first. Speed matters more than anything else.
- Have the bank request a recall of the transfer.
- File a report at ic3.gov.
- Block the lookalike domain in your mail filter and report it to the registrar's abuse contact.
- Check whether your own mailbox was compromised. If the attacker knew details from a real thread, that information came from somewhere.
Frequently asked questions
Can I stop someone from registering a domain similar to mine?
Not entirely, since anyone can register an available domain. You can buy the most likely variations, monitor for new ones, and pursue takedowns when a lookalike is used for fraud or infringes your trademark. Your registrar or a lawyer can advise on formal disputes.
Does DMARC protect against lookalike domains?
No. DMARC only protects your exact domain, and a lookalike is a different domain with its own owner, so it can pass SPF, DKIM and DMARC checks. You still need DMARC, plus impersonation filtering and payment verification for lookalikes.
Is impersonation protection included in Microsoft 365 Business Premium?
Yes. Business Premium includes Defender for Office 365 Plan 1, which provides domain and user impersonation protection. It isn't fully configured by default, so add your own domains, key executives and important vendors to the anti-phishing policy.
How do I check if a lookalike of my domain exists?
Search your domain's common misspellings and alternate endings at any registrar, or use a domain monitoring service that watches new registrations. Your IT provider can also review mail logs for messages from near-match domains that already reached your users.
Not sure whether impersonation protection is actually on in your tenant? We'll check it as part of a complimentary security review and show you what's exposed.
Related reading
CybersecurityMicrosoft 365 Direct Send Abuse: A Phishing Blind Spot
Read Article
CybersecurityQuishing: QR Code Phishing Now Targets Small Business
Read Article
Threat WatchBusiness Email Compromise: How Small Businesses Get Hit
Read ArticleAlso on this topic: Deepfake CFO Fraud Is Here: The $25M Video Call That Fooled Finance · Small Business Cybersecurity: The Controls That Actually Stop Attacks
Discuss microsoft 365 management & backup for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
