Think of a web address you’d recognise instantly – your own company’s, or a supplier you pay every month. Now picture it again with one small change you’d never notice at a glance. One is genuine. The other could easily be sitting in a scammer’s back pocket, waiting for someone to type it in, click it from an email, or simply not notice the difference.
This is the essence of a lookalike domain attack – and it’s a threat that works in two uncomfortable directions. Criminals can impersonate your business to trick your customers, and they can impersonate your suppliers to trick you.
How Lookalike Domains Actually Work
Registering a domain that closely resembles a real one is remarkably cheap and easy, which is exactly why it’s such a popular tactic. A handful of common tricks show up again and again: swapping a letter for a similar-looking one, adding or removing a hyphen, using a different top-level domain such as .com instead of .co.uk, or misspelling a brand name in a way that’s easy to miss when you’re reading quickly.
Some attacks go a step further using what’s known as a homograph technique, where characters from different alphabets that look near-identical to Latin letters are used to build a domain that appears completely genuine to the human eye, even though it’s technically a different string of characters altogether.
Once the domain exists, it can be used in several ways. A fake website can be built to mimic a real login page, harvesting usernames and passwords when people try to sign in. Email addresses can be created using the lookalike domain, making a fraudulent message appear to come from a trusted contact. And the domain itself can simply be parked and used to intercept traffic from people who’ve made a typing mistake.
Two Ways This Threatens Your Business
The first risk is to your own brand. If someone registers a domain that closely resembles yours, they can set up a convincing copy of your website, send emails that appear to come from your business, and potentially deceive your own customers into handing over payment details or personal information. Your business bears the reputational damage, even though you didn’t make the mistake.
The second risk is more direct, and arguably more dangerous: it can be used against you. Imagine an invoice email arriving from a supplier you’ve worked with for years, requesting payment to a new bank account. The sender’s domain looks right at a glance – but it’s one character off from the genuine address. This is a well-established tactic used to redirect payments, and it relies entirely on the fact that most people don’t scrutinise an email address character by character, especially when the message looks routine and the request seems plausible.
For SMEs, this second scenario is often the more costly one. It doesn’t require breaching your systems at all – just enough patience to register a convincing domain and enough polish to make an email look legitimate.
What Can Be Done About It
Complete prevention isn’t realistic – anyone can register a domain that resembles yours, and there’s no way to stop that outright. What matters is reducing the chances of it succeeding, and catching it quickly if it happens.
For protecting your own brand, registering the most obvious variations of your domain – common misspellings, alternative extensions, hyphenated versions – is a simple and inexpensive way to close off the easiest options before someone else takes them. Keeping an eye out for suspicious domains popping up, whether through a periodic manual search or a monitoring service, means you can act before a fake site does real damage.
For protecting against being deceived by a supplier’s lookalike domain, the most effective defence is a habit rather than a technology: verifying any request to change payment details or bank information through a separate, trusted channel, such as a phone call to a known contact number, rather than replying directly to the email. This single habit defeats the vast majority of domain impersonation attempts, regardless of how convincing the fake email looks.
It’s also worth building a quick moment of scrutiny into how staff handle unexpected emails, particularly ones involving payments or sensitive information: a genuine pause to check the sender’s actual domain, not just the display name, before acting.
A Small Detail With Big Consequences
Lookalike domains succeed because they exploit something very human – the tendency to skim rather than scrutinise, especially when a message looks familiar and routine. The good news is that the fix doesn’t require expensive tools or technical expertise, just a habit of checking the details that matter before money or information changes hands.
Worried a lookalike domain could be used to impersonate your business, or that your team might not spot one in a supplier email? Speak to our IT Security team about protecting your brand and your payment processes.

