Typosquatting and Malicious Redirection

To a client, a prospect, or a distracted staff member, the lookalike is indistinguishable. The difference is who owns it.

Law Firm Cybersecurity · Chapter 8~5 min read

An attacker registers a domain that's one keystroke off your firm's — a missing letter, a .co instead of .com, an rn that reads as m — and they have a credible stage for impersonating your firm.

This is typosquatting, and it's cheap, fast, and mostly invisible to the firm being impersonated — because the impersonation happens on infrastructure the firm doesn't own and never sees.

What the lookalike is for

  • Email impersonation. Mail from the lookalike domain passes a glance. It's the delivery vehicle for the wire fraud in Chapter 7 — now with a sender domain that looks right instead of merely a spoofed display name.
  • A credential-harvesting clone. Stand up a copy of the firm's login page on the lookalike domain, drive a target to it, and collect what they type.
  • Malicious redirection. Catch the traffic of people who mistype the firm's address, or who click a link in a doctored email, and send them somewhere hostile — a fake portal, a malware page, a bogus payment page.
FIGURE 1 — FOUR WAYS TO FAKE A DOMAIN
smithlawpartners.com — THE REAL ONE
Character omissionsmithlawparters.com — catches mistyped traffic
Homoglyphsrnithlawpartners.com — rn reads as m in an inbox
Wrong TLDsmithlawpartners.co / .law / .net — passes every glance
Added wordsmithlaw-portal.com — "log in to your client portal"
At a glance, in a client's inbox, on a phone screen — indistinguishable from the real thing.

Why the firm rarely notices

Everything here happens off the firm's own systems. The lookalike is registered elsewhere, hosted elsewhere, sending mail elsewhere. Nothing shows up in the firm's logs because none of it touches the firm's servers. The firm usually learns about it only when a client calls, confused about an email — or worse, after the client already acted on one.

The clients and prospects bear the direct harm, which is precisely what makes this a professional problem and not just a nuisance.

What actually fixes this

1. Lock down your own domain first. Correct SPF, DKIM, and DMARC records make it much harder for a lookalike or spoof to land in an inbox looking legitimate, and give receiving mail servers grounds to reject the fakes.

2. Defensively register the obvious variants. The common typos, the alternate TLDs (.law, .net, .co), the hyphenated "portal" variants. They're cheap. Owning them means an attacker can't.

3. Monitor for lookalikes. Newly registered domains that resemble the firm's are detectable. Watching for them is how you find the impersonation before a client does — the same WHOIS/registration analysis, pointed at yourself.

4. Tell clients how you actually communicate. A simple, standing statement — "we will never email you new wire instructions; payment details are confirmed by phone". This pairs directly with Chapter 7's verification policy.

5. Have a takedown path ready. When a malicious lookalike appears, knowing how to report it to the registrar and host shortens the window it's live.

Request a lookalike-domain scan

Find out who's already registered a domain that looks like yours — plus the SPF/DKIM/DMARC status of your real one.

Your firm's domain security checklist

Spencer McLennan
Spencer McLennan is the founder and lead webmaster of LegalWebmasters, and has handled websites, hosting, and security for law firms and professional practices across the United States and Canada since 2007. He holds an MBA, a PCM from the American Marketing Association, and is a graduate student in intelligence studies. He writes the Law Firm Cybersecurity and Law Firm SEO & Design guides. Connect on LinkedIn.

Trusted by professionals like you.

Crease Harman LLP Borders Law Group David Aujla, Immigration Lawyer