Imagine your firm receives an email from a title company contact you have worked with for years. The display name is right, the signature is right, and the address looks right at a glance. But the domain has an extra letter, or a lowercase "l" replaced by a capital "I," or ".co" where it should be ".com". That small difference is the whole attack.
Lookalike domains are a staple of business email compromise. They are cheap to register, easy to automate, and effective against busy people reading on phones. This post covers how they work and what a firm can do about them.
How Lookalike Domains Work
Attackers use several tricks:
- Typosquatting: a missing, doubled or swapped character, such as "smithlaw" becoming "smithlaww"
- Character substitution: "rn" in place of "m," or the number 1 for the letter l
- Different top-level domain: the same name ending in .co, .net or .us
- Added words: "smithlaw-llp" or "smithlaw-closings"
- Homoglyphs: characters from other alphabets that look identical to Latin letters
- Display-name spoofing: the visible name matches a real person while the actual address is unrelated
They then do one of two things. They email your staff pretending to be a client, opposing counsel or title company, or they email your clients pretending to be you, often with new wiring instructions.
Defend Your Own Domain
Register obvious variants
Consider registering the most likely typos and alternate extensions of your firm's domain. You will not catch everything, but you remove the easiest options.
Set up email authentication
SPF, DKIM and DMARC help receiving servers decide whether a message really came from your domain. A DMARC policy moved to enforcement makes it much harder for someone to send mail that claims to be from your exact domain. It does nothing against a lookalike domain, but it protects your clients from direct spoofing and is an important baseline.
Monitor for new lookalikes
Some email security and domain monitoring services alert you when a similar domain is registered. Ask your provider whether this is available.
Defend Your Staff
Use email security that checks for impersonation
Modern filters flag messages where the display name matches an internal user or frequent contact but the domain is new or unfamiliar. Turn on external-sender banners so staff can see at a glance which messages come from outside.
Train people to read the domain, not the name
Teach a quick routine:
- Look at the full sender address, not just the display name.
- Check the domain letter by letter when money, credentials or documents are involved.
- Hover over links before clicking.
- Be suspicious of a reply that comes from a different address than the original thread.
- Pick up the phone for anything involving payment details.
Save known contacts
Keep real contacts in your address book. A message from an unfamiliar address with a familiar name stands out when autocomplete does not offer it.
Make reporting easy
Add a one-click report button to email and thank people who use it. Fast reports let the firm block a domain before others see it.
What to Do When You Find One
- Report it to your IT provider so the domain can be blocked across the firm.
- Search mailboxes for other messages from the same domain.
- Alert any client or contact being impersonated.
- Report abuse to the domain registrar and hosting provider.
- If money was involved, follow the FBI's guidance: contact your bank right away and file a report with the Internet Crime Complaint Center.
Process Beats Perception
Even careful staff will occasionally miss a lookalike. That is why the final protection should be procedural, not visual: any change to payment instructions gets verified by a call to a known phone number.
How We Help
Counsel Cyber configures email authentication, impersonation filtering and staff training for law firms. If you would like to know how well your domain is protected, we can run a quick review and walk you through the results.