Typosquatting and Malicious Redirection
To a client, a prospect, or a distracted staff member, the lookalike is indistinguishable. The difference is who owns it.
An attacker registers a domain that's one keystroke off your firm's — a missing letter, a .co instead of .com, an rn that reads as m — and they have a credible stage for impersonating your firm.
This is typosquatting, and it's cheap, fast, and mostly invisible to the firm being impersonated — because the impersonation happens on infrastructure the firm doesn't own and never sees.
What the lookalike is for
- Email impersonation. Mail from the lookalike domain passes a glance. It's the delivery vehicle for the wire fraud in Chapter 7 — now with a sender domain that looks right instead of merely a spoofed display name.
- A credential-harvesting clone. Stand up a copy of the firm's login page on the lookalike domain, drive a target to it, and collect what they type.
- Malicious redirection. Catch the traffic of people who mistype the firm's address, or who click a link in a doctored email, and send them somewhere hostile — a fake portal, a malware page, a bogus payment page.
Why the firm rarely notices
Everything here happens off the firm's own systems. The lookalike is registered elsewhere, hosted elsewhere, sending mail elsewhere. Nothing shows up in the firm's logs because none of it touches the firm's servers. The firm usually learns about it only when a client calls, confused about an email — or worse, after the client already acted on one.
The clients and prospects bear the direct harm, which is precisely what makes this a professional problem and not just a nuisance.
What actually fixes this
1. Lock down your own domain first. Correct SPF, DKIM, and DMARC records make it much harder for a lookalike or spoof to land in an inbox looking legitimate, and give receiving mail servers grounds to reject the fakes.
2. Defensively register the obvious variants. The common typos, the alternate TLDs (.law, .net, .co), the hyphenated "portal" variants. They're cheap. Owning them means an attacker can't.
3. Monitor for lookalikes. Newly registered domains that resemble the firm's are detectable. Watching for them is how you find the impersonation before a client does — the same WHOIS/registration analysis, pointed at yourself.
4. Tell clients how you actually communicate. A simple, standing statement — "we will never email you new wire instructions; payment details are confirmed by phone". This pairs directly with Chapter 7's verification policy.
5. Have a takedown path ready. When a malicious lookalike appears, knowing how to report it to the registrar and host shortens the window it's live.
Find out who's already registered a domain that looks like yours — plus the SPF/DKIM/DMARC status of your real one.
Your firm's domain security checklist
