What is Lookalike Domains?
Lookalike domains are registered names that visually or typographically resemble a trusted brand — rn instead of m, extra letters, or alternate TLDs. They power phishing sites, fraudulent invoices, and executive impersonation that bypass casual visual checks.
How a Lookalike Domains Attack Works
Enumerate brand variants
Attackers generate permutations of your corporate and vendor domains.
Register cheap lookalikes
Newly available or aged domains are purchased, often with privacy protection.
Stand up infrastructure
They clone login pages or send mail from the lookalike to finance and executives.
Monetize trust
Credential theft or redirected payments follow once someone trusts the familiar name.
Real-World Example
A law firm nearly wired settlement funds after receiving instructions from a domain that swapped one character in the title company's name. The real closing details were copied from a public court calendar.
How AiVERSARY Detects Lookalike Domains Risk
AiVersary reconnaissance looks for brand-adjacent domain activity and the public cues attackers use to pick which brands to spoof — so you can monitor and warn staff before a campaign hits.
Is your organization exposed to lookalike domains?
AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.
Get Your Threat ReportRelated Terms
Business Email Compromise
Business email compromise is when an attacker impersonates a senior executive — usually the CEO or CFO — to trick an employee into wiring money or sharing sensitive data. These attacks don't require any malware or hacking; they rely entirely on convincing someone that a fraudulent request is coming from their boss. The FBI reports BEC has caused over $50 billion in losses worldwide.
Spear Phishing
Spear phishing is a targeted email attack where criminals research a specific person and craft a message designed just for them. Unlike mass spam, these emails reference real details about your job, your colleagues, or recent company events to appear legitimate. They are the number one way attackers breach organizations today.
Vendor Email Compromise
Vendor email compromise is BEC aimed through a trusted supplier. Attackers breach or spoof a vendor, then send altered invoices or payment instructions to that vendor's customers — riding existing business relationships that finance teams already trust.
OSINT Reconnaissance
OSINT reconnaissance — Open Source Intelligence gathering — is the first phase of nearly every targeted cyberattack. It's the process of collecting publicly available information about an organization and its people to plan an attack. Everything from your company website and LinkedIn profiles to job postings, DNS records, and conference presentations becomes intelligence. This is exactly the same process AiVersary uses, but we do it first so you can fix what's exposed.