How it works
Lookalikes use any trick that makes a domain pass for yours: alternative endings, inserted hyphens or words, swapped characters, or subdomains that bury your brand, as in "yourbrand.login-secure.com". Once registered, they host phishing, fake shops, or spoofed email.
How it relates to brand impersonation
The lookalike domain is the most common building block of brand impersonation. Catching new ones at registration is the earliest possible point of intervention, before any victim is reached.
How nebty helps
nebty continuously discovers lookalike domains targeting your brand, scores them by risk, and lets you escalate the dangerous ones to an on-demand takedown that you only pay for on success.
Domain monitoringThe trick categories to watch
Lookalike is an umbrella, and the families underneath it are worth knowing because each needs a different detection rule. There are typos (a slipped or doubled letter), combinations (your brand plus a word like login or pay), homoglyphs (foreign characters that look identical), and alternative endings (your brand on .net, .shop, or a country code you do not own). A sneakier family buries your brand in a subdomain, so yourbrand.account-verify.com looks right at a glance even though the real owner is account-verify.com. No single rule catches all of these, which is why effective monitoring generates each variant family separately and then ranks the results, so the dangerous, ready-to-use lookalikes rise above the parked or harmless ones.
Prioritise by readiness, not similarity alone, because a lookalike with live hosting, a certificate, and mail records is a campaign in waiting, while a parked one can usually wait too.
A concrete example
A monitoring sweep around the brand Solara Finance surfaces four new domains in one week: solarafinance.shop, solara-finanse.com, solara-finance-login.com, and solarafinance.de. Three are parked and get a watch flag. One, solara-finance-login.com, already has live hosting, a fresh TLS certificate, and mail records. That combination means someone is about to use it. It goes straight to takedown, and the phishing campaign it was built for never launches.
How to spot and stop it
- Watch new domain registrations and certificate transparency logs for names close to yours. Both are public and catch most lookalikes on day one.
- Score findings by readiness, not similarity alone. Live hosting, a certificate, and mail records mark a lookalike that is about to be used.
- Escalate the ready ones to a takedown before the campaign starts. A parked lookalike can be watched; an armed one should not be.
Frequently asked questions
Are lookalike domains illegal?
Registration alone usually is not. The moment a lookalike hosts phishing, a fake shop, or spoofed email, it violates abuse policies and often trademark and fraud law, which is what takedowns and UDRP proceedings build on.
How do I find lookalike domains targeting my brand?
One-off checks work with open tools that generate typo and combination variants and query WHOIS and DNS. For anything you depend on, continuous monitoring of registrations and certificate logs is the reliable route, because new lookalikes appear daily.
What should I do when I find one?
Document it, check whether it is parked or armed, and act on the armed ones: report to the registrar and host, submit phishing pages to blocklists, and escalate to a takedown. Keep watching the parked ones, since they can arm later.
Related terms
See who is impersonating your brand
The free nebty report scans the web for lookalike domains and fake profiles targeting your brand, with no obligation.
Get your free report