Skip to main content

Domain spoofing

Domain spoofing is faking a trusted domain, in a website URL or an email sender address, to make fraudulent content appear to come from a legitimate brand.

How it works

There are two main flavours. Website spoofing uses a lookalike domain to host a copy of your site. Email spoofing forges the "From" address so messages appear to come from your domain. The email kind is preventable with SPF, DKIM, and DMARC, but only when those records are correctly enforced.

How it relates to brand impersonation

Domain spoofing is how attackers borrow your identity at scale. It underpins phishing, business email compromise, and fake-invoice fraud, all forms of brand impersonation that exploit the trust attached to your domain.

How nebty helps

nebty monitors for the lookalike domains used to spoof your brand and can take spoofing infrastructure down on demand, complementing your own SPF, DKIM, and DMARC hardening.

Domain monitoring

Website spoofing versus email spoofing

It helps to separate the two things people mean by domain spoofing, because the defences differ. Website spoofing hosts a copy of your site on a lookalike domain, and the answer is monitoring plus a takedown of the offending domain. Email spoofing forges the From address so a message appears to come from your domain, and the answer there is email authentication: SPF lists who may send for you, DKIM signs the message, and DMARC tells receivers what to do when those checks fail. With DMARC set to reject, direct spoofing of your exact domain largely stops, which simply pushes attackers onto lookalike sender domains instead. So the two defences are complementary: authentication closes your own domain, and monitoring plus takedowns handle the lookalikes attackers move to.

A concrete example

A supplier of Solara Finance receives an email that appears to come from [email protected], asking to update the bank details for the next invoice. The From address is forged; Solara Finance never enforced its DMARC policy, so receiving servers had no instruction to reject the fake. After the incident the company moves DMARC to reject, and direct spoofing of the exact domain stops. Two months later the same fraud attempt returns from [email protected], a lookalike, and gets caught by monitoring instead.

How to spot and stop it

  1. Enforce SPF, DKIM, and DMARC on your own domain, with DMARC at reject. This closes direct spoofing of your exact domain.
  2. Monitor for lookalike domains, because enforcement pushes attackers onto solarafinance-payments.com-style senders that your DNS records cannot cover.
  3. For payment or account changes, verify over a second, known channel. A forged domain survives every visual check.

Frequently asked questions

Does DMARC stop domain spoofing?

It stops spoofing of your exact domain once the policy is set to reject. It does nothing against lookalike domains, which is where attackers move next. You need both enforcement and monitoring.

How do I know if my domain is being spoofed?

Publish a DMARC record and read the aggregate reports: they list every server sending mail as your domain, legitimate and not. Complaints from customers or partners about emails you never sent are the louder, later signal.

See who is impersonating your brand

The free nebty report scans the web for lookalike domains and fake profiles targeting your brand, with no obligation.

Get your free report