How to detect lookalike domains before they go live
Nearly every phishing campaign starts with a domain. Before there is a cloned login page, before a single email goes out, an attacker registers a web address designed to look like yours. Catch that domain early and you can be watching the trap before it is set. Miss it, and you are reacting after your customers have already been hit.
Here is how lookalike domains are built — and the signals that expose them before they go live.
The families of lookalike
Typosquatting
The oldest trick: register the domains people reach by mistyping yours. Dropped letters, doubled letters, swapped adjacent keys, a .co where the real site is .com. Each variant quietly collects traffic from fumbled keystrokes.
Homoglyph (look-alike character) attacks
Some characters are visually identical but technically different — a Latin a versus a Cyrillic а, a lowercase l versus a capital I, a zero versus a capital O. A homoglyph domain can look pixel-perfect in an address bar while pointing somewhere entirely different.
Combosquatting
Here the real brand name is kept intact but surrounded by plausible words: brand-secure, brand-login, brand-support, my-brand-account. Because the brand is spelled correctly, these are especially convincing — and especially common in phishing.
TLD and subdomain tricks
The brand sits on an unexpected ending (brand.app, brand.help) or is buried in a subdomain of an unrelated domain (brand.com.secure-login.net), where a hurried reader sees the brand first and stops reading.
The common thread: all of these are designed to pass a half-second glance. Detection cannot rely on people noticing — it has to be systematic.
The signals that expose them
You do not have to wait for a lookalike to attack. Several signals surface them early, often before any content exists:
- New-registration feeds. Newly registered domains can be scanned for names that are a small edit-distance from your brand, or that contain it plus a common phishing word.
- Certificate transparency logs. When a domain gets a TLS certificate, it is logged publicly. Watching these logs reveals lookalikes the moment they prepare to serve HTTPS — usually just before going live.
- Edit-distance and homoglyph matching. Algorithmic comparison catches both typos and look-alike-character swaps that a keyword filter would miss.
- Keyword permutations. Generating the plausible combosquatting patterns around your brand and watching for any of them to be registered.
- Passive DNS and hosting overlap. Lookalikes often share infrastructure with known bad actors, so a new domain on a flagged host is worth immediate attention.
From signal to action
Finding a lookalike is the start, not the end. What you do next depends on what the domain is doing:
- Dormant. No content yet. Watch it closely; record the registration and infrastructure so you are ready the instant it activates.
- Live with a clone. It is serving a phishing page — often cloaked. Capture dual-profile evidence and move straight to a takedown.
- Sending mail. It is being used for phishing email. The sending behaviour is itself reportable abuse, on top of any hosted content.
Phish Plug watches new-registration feeds and certificate transparency logs for lookalikes of your brand, then — the moment one serves a clone — crawls it as a bot and a real phone to prove any cloaking and build the case automatically.
Why early detection changes the math
A lookalike caught at registration gives you days of lead time. You already know the domain, its registrar and its host before it is weaponised, so when it finally serves a clone, the takedown report is complete on day one — not assembled in a panic after customers report losing money. Early detection turns a scramble into a routine.
The takeaway
Lookalike domains are the foundation every phishing clone is built on, and they are deliberately easy to overlook. Systematic detection — edit-distance and homoglyph matching against new registrations and certificate logs — moves you ahead of the attacker. Watch the domain before the trap is set, and you remove the clone before it ever reaches the people you are protecting.
Keep reading
Related articles
Fake login pages: how to spot one before you type
Cloned sign-in screens are the sharp end of phishing. The tells that give them away, and why your customers need you watching rather than relying on their eyes.
Read article Best practices · 10 minBrand protection best practices: a checklist for 2026
A practical playbook for protecting your brand from phishing impersonation — monitoring, evidence, takedowns and the metrics that matter.
Read article Threats · 8 minBrand impersonation on social media: a response playbook
Fake profiles, cloned pages and lookalike handles target your customers off your own site. How to find, evidence and take down social impersonation.
Read articleFind the lookalikes targeting your brand
Run a free clone check — we surface lookalike domains and prove any cloaking on one of yours.