Skip to content

Free Tools/Domain Lookalike Checker

Is someone squatting on a copy of your domain?

Invoice fraud usually starts with a domain one character off from a real one: yourcornpany.com instead of yourcompany.com. We'll generate the common lookalike tricks for your domain and check which ones someone has already registered.

Read-only public DNS lookups, nothing is stored. The scan checks roughly 100 common variants and takes about ten seconds.

The tricks this scan looks for

Swapped or missing letters

acmesupply.com becomes acmesuply.com or acmesupplu.com. Typos your eye corrects automatically, which is exactly the point.

Lookalike characters

The letters "rn" reads as "m" in many fonts, a zero passes for the letter o, and a capital I passes for a lowercase l. Classic invoice-fraud material.

Different endings

Your .com registered as .co, .net, .us, or .info by someone else. The email address looks nearly identical to yours.

Add-on words

yourcompany-billing.com or yourcompany-support.com. These don't even need a typo; they borrow your name's credibility outright.

The most dangerous finding is a lookalike with mail servers configured, because it can send email that appears to be from your business. And remember the other half of the defense: locking down your real domain with DMARC, SPF, and DKIMso scammers can't simply use your exact address instead.

Common questions

Why would someone register a lookalike of my domain?

The most common reason is business email compromise: a scammer registers a near-copy of your domain, then emails your customers or your own staff posing as you, often to redirect an invoice payment. Because the address looks right at a glance, these scams succeed at an alarming rate. Lookalikes are also used for fake websites and credential-stealing login pages.

A lookalike of my domain exists. Should I panic?

Not necessarily. Many registered lookalikes are unrelated legitimate businesses, domain speculators hoping to resell, or parked pages, and some companies defensively register their own lookalikes (it may even be yours). The ones to take seriously are recently registered variants with mail servers configured, since those can send email. Worth a closer look either way, and we can help you dig in.

What can I actually do about lookalike domains?

Three practical moves. First, defensively register the handful of highest-risk variants yourself; a few domains a year is cheap insurance. Second, make sure your real domain has strong email authentication (DMARC, SPF, DKIM) so at least your exact domain can't also be spoofed. Third, train your team to check sender addresses character by character on any email involving money or credentials. If a lookalike is actively impersonating you, trademark-based takedown processes exist, and we can point you in the right direction.

Does this check every possible lookalike?

No. We check a few dozen of the most common tricks: swapped and doubled letters, lookalike characters, different domain endings, and typical add-on words like "-support". A determined attacker has more options than any scanner can enumerate, including accented characters and completely different endings. Treat a clean result as "nothing obvious", not "nothing possible".

Found something that worries you?

We can investigate suspicious lookalikes, lock down your email authentication, and set up ongoing monitoring so you hear about new imposters before your customers do.