Domain impersonation

The certificate shows up before the phishing email does.

Someone registering a name to look like yours has to leave two public traces before they can use it: the registration itself, and a certificate published to a transparency log. Both are readable by anyone. This page covers the four signals in the order they arrive, how to triage what you find, and what can realistically be done about it.

The lookalike check runs without an account. It reads public DNS, registry and certificate records only, never visits the other domain, and will not run against banks, government sites or the major platforms. Keeping the results, and watching for new lookalikes, is what the account is for.

The four signals

In the order they actually reach you.

First

A certificate appears in a public log

Minutes after the attacker sets up HTTPS, usually days before the first phishing email

Certificate Transparency is an append-only public log of issued certificates, defined in RFC 6962 and its successor RFC 9162. Since 30 April 2018 Chrome refuses to trust a publicly issued certificate that does not come with proof of being logged, so in practice every certificate on the public web is published, by name, within minutes of issuance. A phishing page needs HTTPS to look convincing. That requirement is what makes it visible before it is used.

Where to look: A public CT index such as crt.sh, searched for your brand as a substring.

Second

A registration appears that reads like yours

Whenever the attacker buys the name, which may be months in advance

Four shapes account for most of it: a typo (a dropped or doubled letter), your name plus a word (billing, secure, support, pay), which is not a typo at all and is the most common shape in business email fraud, the same name on a different ending, and characters from other alphabets that render as Latin letters. That last one is never accidental; nobody types a Cyrillic a by mistake.

Where to look: A lookalike scan over registration data, run regularly rather than once.

Third

Your own DMARC reports name an IP you do not recognize

Within a day of the first spoofed message, if you have DMARC reporting on

This is a different attack from a lookalike domain: it is someone sending mail with your exact domain in the From: line. A DMARC aggregate report lists every source IP that did so, with a count and a verdict. If you have never published a DMARC record, this signal does not exist for you, and turning it on costs one DNS record and changes nothing about delivery.

Where to look: The aggregate reports mailbox providers send to the rua= address in your DMARC record.

Fourth

A customer tells you

After the money has moved

By the time somebody calls to ask whether the invoice was really from you, the answer has already cost someone. It is still worth capturing properly, since the email headers from that message are the best evidence you will get, but treating this as your detection method means detecting things after they happen.

Where to look: Your inbox, and whoever answers the phone.

Reading a CT entry

What a lookalike looks like in a certificate log.

A log entry is a certificate, not a verdict. Four parts of it carry almost all the signal, and none of them require any tooling to read.

The subject alternative names

The list of hostnames the certificate covers. A lookalike usually shows two: the bare name and its www form. Two or three unrelated brands in one SAN list is a bulk phishing operation being lazy.

The issuer

Overwhelmingly a free, automated CA. That is not suspicious by itself, since most of the legitimate web uses one too, but combined with a name that resembles yours and a registration from last week, it is the pattern.

The not-before timestamp

When the certificate became valid, which is effectively when the site was being set up. Compare it to the domain's registration date: a name registered on Monday with a certificate on Tuesday was bought to be used.

A wildcard, or a mail hostname

A wildcard means they intend to run many subdomains, which is a campaign rather than a one-off. A certificate covering a mail hostname means they are preparing to send, and that moves it to the top of your list.

Triage

Four questions, in this order, about every name you find.

A list of similar domains is not a list of threats. Most registered lookalikes are dormant, some belong to legitimate businesses, and a few are being prepared right now. The mail question separates them faster than anything else.

Does it have MX records?

Query the MX records for the lookalike name. If it can receive mail, it is almost certainly built to send mail.

Act today.

Does it have a certificate?

Check the CT logs for the name. A certificate means somebody stood up a TLS listener for it, which costs effort nobody spends on a name they are sitting on.

Act this week.

Does it resolve, and to what?

An A record pointing at a parking page is different from one pointing at a live copy of your homepage. Look at what is actually served before deciding.

Watch it.

Was it registered recently, and by whom?

The registry record gives you the creation date and the sponsoring registrar. A name registered years ago by a legitimate business that happens to resemble yours is a trademark question, not a security one.

Depends entirely on this answer.

Before you file anything

Six things to collect, and one to be careful about.

  • The registry record: creation date, sponsoring registrar, and the registrar's abuse contact. Since January 2025 that data comes from RDAP rather than WHOIS for generic top-level domains.
  • The DNS records as they stand right now, with the time you read them. A and MX especially. These change, and an abuse desk will ask what you saw.
  • The certificate from the Certificate Transparency log, including its issuance timestamp and the full list of names it covers.
  • Screenshots of what the site serves, with the URL bar visible. If it is a copy of your site, say which pages.
  • The full headers of any phishing message, not a forwarded copy. Forwarding rewrites the headers and destroys the part that identifies the sender.
  • Your own trademark registration number, if you have one. It is what turns a complaint into a filing.

The one to be careful about: do not go poking at the other domain. Logging in with a fake credential to see what happens, scanning its ports, or downloading what it serves can put you on the wrong side of a computer misuse law and taints the evidence you already have. Reading public DNS, public registry data and public certificate logs is not the same thing, and it is enough for every route below.

What can actually be done

Four routes, with honest timelines.

Report to the registrar

Every ICANN-accredited registrar publishes an abuse contact and is obliged to act on reports. This is the fastest route and the one with the lowest bar: you are reporting fraud, not asserting a trademark.

Days to weeks, and it depends heavily on the registrar.

Report to the hosting provider

Separate from the registrar and often more responsive, because the content is on their machines. Find the host from the IP address the name resolves to.

Often the quickest way to take the page down, even if the name stays registered.

Report the URL to browser safe-browsing services

Google Safe Browsing and Microsoft SmartScreen take public phishing reports. This does not remove anything, but it puts a full-page warning in front of most people who click the link.

Hours to days, and it protects victims while the slower routes run.

File a UDRP or URS complaint

The Uniform Domain-Name Dispute-Resolution Policy is ICANN's arbitration process for a domain registered in bad faith that is confusingly similar to a mark you hold. The Uniform Rapid Suspension system is its faster, cheaper sibling for clear-cut cases in newer top-level domains, and it suspends rather than transfers.

Weeks to months, with filing fees. It needs a trademark, and it is the only route that ends with you owning the name.

How DomainGuard helps

Find it, rank it by mail, hand you the evidence.

The free check

Generates the variants attackers actually buy (typos, your name plus a word, other endings, lookalike characters) and checks which of them are registered, which resolve, and which can receive mail. It reads public records only and never visits the other domain.

The watch

A paid feature: the same scan on a schedule, with an alert the day a lookalike gains an MX record or a certificate. A dormant name becoming an active one is the event worth waking up for, and it is the one a single manual check will always miss.

What we do not do

We do not file complaints, take domains down, or tell you that a registration is fraud. A domain somebody registered is a fact; why they registered it is a judgment, and we give you the evidence rather than the verdict.

Questions people actually ask

What does a lookalike domain look like in Certificate Transparency logs?

A certificate entry whose subject alternative names include a name close to yours — a typo, your name plus a word like billing or secure, or the same name on a different ending. It is usually issued by a free automated certificate authority, it usually covers just the bare name and its www form, and its issuance timestamp is often within days of the domain's registration date. That gap between registration and certificate is the window you get.

Why does a certificate show up before the phishing email?

Because a convincing phishing page needs a padlock, and since April 2018 Chrome will not trust a publicly issued certificate unless it has been published to a Certificate Transparency log. The attacker has to publish the name to use it, and publication happens at setup time, not at attack time.

Someone registered a domain like mine. Which one should I worry about?

Sort by whether it can receive mail. A lookalike with MX records is being prepared to send invoices as you, and that is today's problem. A lookalike with a certificate but no mail is being prepared to host a page. A registered name with neither is worth recording and watching, not panicking about.

Can I get a lookalike domain taken down?

Sometimes, and not cheaply or quickly. The realistic order is: report abuse to the registrar and the hosting provider, report the URL to Google Safe Browsing and Microsoft SmartScreen so visitors get a warning, and if you hold a trademark, file a UDRP or a URS complaint. Anyone offering fast guaranteed takedowns for a small fee is selling you the first two steps.

What does DomainGuard do here?

The free lookalike check finds names registered to resemble yours and pays particular attention to whether each one can receive mail, using public DNS, registry and certificate-log data. It never visits the other domain. Continuous watching, meaning the nightly re-scan and the alert when a lookalike gains mail or a certificate, is a paid feature. We collect the evidence; filing is yours.