Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Phishing infrastructure
Reference · Pattern

Lookalike domain registered against the corporate brand

Severity HighKind Phishing infrastructureEffort to fix ModerateUpdated 29 Sep 2026By LeakTrace
Definition

A recently-registered domain uses a visual or typographical variation of the corporate name (typo-squat, IDN homograph, tenant-suffix squat) and is likely being staged for wire-fraud pretext.

What it is

Lookalike domain registration is a leading indicator of wire-fraud pretext staging. The attacker registers <company>-secure.com, <company>llc.net, or <c0mpany>.com (with a zero for the o) roughly 7-14 days before the intended attack, then sets up email records that pass SPF/DKIM/DMARC on the lookalike domain itself. From there, they send authentic-looking mail to targets who weren't explicitly told about the imposter domain.

Why it matters

The lookalike domain gives the attacker a working sender that will not be caught by any of the target firm's inbound mail defenses, no DMARC policy on the parent domain will help, because the mail is not sent from the parent domain, it's sent from the lookalike. Every email defense that operates on sender authentication is bypassed.

How anyone can check it

whois yourfirm-ca.com

Try two or three misspellings of your domain and see which are registered.

Remediation direction

Daily re-checking of new domain registrations for typo-squats, IDN homographs, and tenant-suffix variations of the corporate brand, combined with a mail-security rule that flags any inbound mail from a domain visually similar to the corporate domain. When a genuinely-malicious lookalike is confirmed, use hosting-provider abuse channels for takedown.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →