ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Lookalike Domains and Display-Name Spoofing: Spotting Fake Senders

Criminals register near-identical domains and fake display names to impersonate attorneys. Learn how to spot fake senders and how filters reduce the risk.

3 min readBy Counsel Cyber Team

The email looks right. The name is a managing partner's. The signature is familiar. The only problem is that the address behind the name ends in a domain that is one character off from the firm's real one, or is a free webmail address with the partner's name on it. Impersonation of this kind is among the cheapest and most effective tricks in the criminal playbook, and it targets law firms because they move money and handle sensitive information.

The FBI's Internet Crime Complaint Center has described business email compromise as a persistent financial threat. Many of those schemes rely on impersonation instead of any technical break-in. Understanding the common variants helps staff catch them.

The main tricks

Display-name spoofing

Email clients show a friendly name before the address. Anyone can set that name to anything. On a phone, where only the name appears, a message that says "Jane Partner" may actually come from a random address. This requires no domain registration at all.

Lookalike domains

Criminals register domains that resemble the real one by:

  • Swapping similar characters, such as a lowercase letter L for the capital letter I, or the letters "rn" for an "m".
  • Adding or dropping a letter.
  • Appending words like "law" or "legal" or changing the ending from .com to .net.
  • Using lookalike characters from other alphabets.

They then set up mailboxes and send convincing messages, often replying inside a real conversation after seeing a thread through another compromised account.

Reply-to manipulation

A message may appear to come from a trusted address but carry a different reply-to. When the recipient answers, the response goes to the criminal.

Compromised third parties

Messages from a genuine but hijacked account at a title company, lender or client are the hardest to detect, since the sender and domain are legitimate. That is why verification by phone matters even with perfectly authentic-looking mail.

Habits that catch fakes

  1. Check the full address, not just the name. On a phone, tap or expand the sender details.
  2. Read the domain slowly, letter by letter, especially on anything involving money or credentials.
  3. Hover over links before clicking, and be suspicious of unexpected attachments.
  4. Look at the reply-to when answering a request for money, documents or access.
  5. Notice urgency, secrecy and requests to bypass normal process. These are pressure tactics.
  6. Verify by phone using a number you already have, not one in the message.

Technical controls

External sender banners

Configure the email system to label messages from outside the firm, so an unexpected "internal" executive request that carries an external tag stands out.

Impersonation protection

Modern email security tools can flag messages where the display name matches a known partner but the address does not, and can detect domains similar to yours. Ask your provider whether such protection is enabled, and add your leadership's names to a protected list.

Authentication records

Publishing SPF, DKIM and DMARC and enforcing a strict policy prevents criminals from sending mail that truly claims to be from your exact domain. It does not stop lookalike domains, but it removes the easiest option.

Register defensive domains

Consider registering obvious variations of your domain, such as common misspellings and other endings, and keep them parked with a no-send email policy. This is not exhaustive, but it covers the most predictable cases.

Monitor for new lookalikes

Some services alert you when a domain similar to yours is newly registered. This is optional but helpful for larger firms or those frequently targeted.

Train with examples

Show staff real examples of display-name and lookalike emails with names redacted. Run periodic phishing simulations, and focus on reporting rather than punishment. Make a one-click "report this email" button available so that reporting is easier than ignoring.

What to do if you replied

Tell IT immediately. Do not delete the message. If you sent credentials, change passwords and revoke sessions. If you sent or planned money, call your bank at once. Quick reporting is more valuable than embarrassment management.

Remember the limits

No single check catches everything. Layers, including filtering, authentication, training and phone verification, work together. The most reliable defense for payments remains a procedure that does not depend on judging whether an email looks real.

How Counsel Cyber helps

Counsel Cyber configures impersonation protection, authentication records and reporting tools for law firms, and trains staff using realistic examples. Ask us for an email security review if you want to see how your firm would handle a convincing fake.