What Is a Lookalike Domain (and Why Should Your Business Care)?

If a web address looks like yours at a glance, it can be used to borrow your good name and deceive your customers. These copycat addresses are called lookalike domains. This guide explains what they are, the different forms they take, and what you can do about them, all in plain English.

What a Lookalike Domain Is

A lookalike domain is a web address chosen to resemble a real one closely enough to be mistaken for it. Your domain is the main name in your web and email addresses — for example, "yourbusiness.co.uk". A lookalike is a different domain, controlled by someone else, that may be designed to pass for yours.

The resemblance can come from a misspelling, a different ending, a reworded version of your name, or letters that look identical but are technically different. The point is the same: to make a person glance at the address, recognise your brand and trust it. Lookalike domains are a common tool in the wider problem we describe in our guide to domain impersonation.

The Different Kinds of Lookalike Domain

Lookalikes come in a few recognisable forms, and knowing them helps you spot the trick.

Misspellings, where the fraudster registers common typing mistakes of your name. This particular tactic is known as typosquatting, and we cover it in detail in our guide to typosquatting.

Different endings, where the name is spelled correctly but the ending is changed, such as ".com" instead of ".co.uk", or ".net", ".info" or ".shop" instead of your real one. Many customers do not notice or remember which ending your business actually uses.

Reworded names, where the fraudster keeps your brand but rearranges or adds to it, such as swapping word order, adding a hyphen, or inserting a small extra word.

Lookalike letters, where a Latin letter is swapped for a similar-looking character from another writing system. This trick is powerful enough to deserve its own explanation, which you will find in our guide to homoglyph attacks.

Brand-plus-word addresses, where an official-sounding word such as "login", "secure" or "billing" is bolted onto your name. We cover these in our guide to combosquatting.

Why Lookalike Domains Are a Serious Risk

A lookalike domain on its own is not proof of abuse, but it can be the starting point for real harm. Its owner can build a copy of your website to take fraudulent orders or steal login details. They can also use the domain in deceptive emails, including fake-invoice scams, or place it in links sent by text or email.

The people fooled are almost never you. They are your customers, suppliers and staff, and when they are caught out they often believe it was really your business that let them down. For a small firm that lives on reputation, that loss of trust can cost far more than the fraud itself.

How to Spot and Stop Lookalike Domains

There are three practical things a business can do.

Know your own exact address and share it clearly. Make sure your genuine web address appears consistently on your site, emails, invoices and signage, and encourage customers to check it. The clearer your real address, the easier a fake is to notice.

Register selected high-priority lookalikes yourself. Buying, renewing and securing the nearest misspellings or common alternative endings keeps those exact domains under your control. You cannot own every possibility, so our guide to defensive domain registration explains how to choose.

Keep watch for the rest. Because there are far too many possible lookalikes to buy them all, the practical safety net is to be alerted when someone registers one. Doing that by hand would mean generating and checking endless variations, over and over, which no busy owner has time for. This is exactly what Impostor Watch does for you.

How Impostor Watch Helps

Impostor Watch uses public Certificate Transparency logs, newly registered domain feeds and generated variations to look for domains that resemble your name, including lookalike-letter tricks. When it finds a match, it checks for a live website, mail records and signs such as a copy of your site's small browser icon (its favicon), then explains the apparent risk in plain English.

That removes the two hardest parts of protecting yourself: imagining every possible fake, and finding the time to keep checking. If a lookalike needs removing, you can ask us to handle it. You can start with a one-off report or turn on continuous monitoring for a small monthly fee.

Frequently Asked Questions

What is the difference between a lookalike domain and typosquatting?

Typosquatting is one kind of lookalike domain, specifically misspellings of your name. Lookalike domain is the broader term that also covers different endings, reworded names, lookalike letters and brand-plus-word addresses.

Are lookalike domains against the law?

Registering a similar domain is not automatically unlawful. Using one for fraud, passing off or trade mark infringement may be. A genuine unrelated business may have a legitimate reason for a similar name, so the evidence, your rights and how the domain is being used all matter.

How do I find lookalike domains targeting my business?

You can check obvious variations yourself, but do not visit a suspicious site merely to investigate it. A monitoring service such as Impostor Watch can repeatedly check a much broader set of signals and alert you when it detects a new match.

Curious which lookalikes are active in DNS? Run a free scan with Impostor Watch to see which generated variations are registered and point to an internet address.

Check for lookalike domains

Run a free check for lookalike domains that are registered and point to an internet address — no sign-up, nothing to install.

Run a free scan Or see a sample Domain Report →