What it is
Lookalike domain registration is a leading indicator of wire-fraud pretext staging. The attacker registers <company>-secure.com, <company>llc.net, or <c0mpany>.com (with a zero for the o) roughly 7-14 days before the intended attack, then sets up email records that pass SPF/DKIM/DMARC on the lookalike domain itself. From there, they send authentic-looking mail to targets who weren't explicitly told about the imposter domain.
Why it matters
The lookalike domain gives the attacker a working sender that will not be caught by any of the target firm's inbound mail defenses, no DMARC policy on the parent domain will help, because the mail is not sent from the parent domain, it's sent from the lookalike. Every email defense that operates on sender authentication is bypassed.
How anyone can check it
whois yourfirm-ca.comTry two or three misspellings of your domain and see which are registered.
Remediation direction
Daily re-checking of new domain registrations for typo-squats, IDN homographs, and tenant-suffix variations of the corporate brand, combined with a mail-security rule that flags any inbound mail from a domain visually similar to the corporate domain. When a genuinely-malicious lookalike is confirmed, use hosting-provider abuse channels for takedown.
LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.