Common impersonation techniques
Domain impersonation relies on a target not reading a domain name carefully. Typosquatting substitutes, adds or removes a character close to a genuine name, such as transposed letters or a doubled letter. Combosquatting adds extra words around a genuine brand name, such as pairing it with 'secure' or 'support'. Homoglyph attacks replace one or more characters with a visually similar character from another script, often rendered through internationalized domain name encoding beginning xn--, which looks identical or near-identical when displayed but is a completely different registration underneath.
A different top-level domain is also a frequent and low-effort technique: registering the exact same name under .net, .co or a less common country-code or new generic TLD when the brand is known for operating on .com. None of these techniques require compromising the real organisation at all; they only require registering an available, similar-looking name.
Recognising it in practice
The resemblance itself is only a lead. Confirm the registrable domain involved, since 'brand.example.net' is controlled by example.net regardless of the subdomain label chosen. Compare the suspect domain's RDAP creation date, registrar and nameservers against the genuine organisation's known domain; a very recent registration date combined with a close resemblance to a known brand is a strong combination of signals, though recency alone is common among legitimate new projects too.
Mail and certificate evidence can add further context: an impersonation domain configured to receive mail, or one that has recently obtained its first TLS certificate, suggests active preparation for use rather than passive or speculative registration.
Why monitoring matters
Because new impersonation domains can appear at any time, a single point-in-time check only tells you about what already exists. Ongoing monitoring of a brand's name variations, combined with periodic WHOIS comparison on domains already being tracked, helps surface a new lookalike registration or a change to an existing watched domain's registration data soon after it happens, rather than after it has already been used against customers or staff. For Unlimited subscribers, domain monitoring runs weekly WHOIS diffs and lookalike checks on the domains being tracked, flagging newly registered similar names and registration changes for review.
Responding appropriately
Treat a detected lookalike as something to verify and, where warranted, report through the registrar's or host's abuse process with specific evidence, not as grounds for public accusation on its own. Preserve the evidence that led to the detection, including the comparison with the genuine domain, before requesting takedown action.
- Identify the technique: typosquat, combosquat, homoglyph or alternate TLD.
- Confirm the registrable domain, not just a subdomain label.
- Compare registration date, registrar and nameservers with the genuine domain.
- Check mail and certificate activity for signs of active preparation.
- Use ongoing monitoring to catch new lookalikes as they are registered.
