How Fraudsters Use Lookalike Domains for Business Email Compromise
A domain that differs from a genuine vendor's by a single swapped or added character is often enough to redirect a real invoice payment straight into a fraudster's account.


In Simple Terms (For Beginners)
A lookalike domain is a website or email address deliberately crafted to resemble a real one, often by swapping a letter, adding a hyphen, or using a different top-level ending, so a quick glance mistakes it for the genuine business.
- Lookalike domains let attackers send emails that pass a casual visual check while actually coming from an address the real vendor doesn't own.
- Business email compromise using this technique often targets an invoice or payment already in progress, making the timing look natural.
- Checking the sender's actual domain character by character, not just the display name, is the most reliable single defence.
THREAT INTEL · October 4, 2026 · 6 min · By Hardik Patel
How do fraudsters use lookalike domains for business email compromise? An attacker registers a domain that closely resembles a real vendor's, often swapping a single letter or adding a hyphen, then emails a business mid-transaction pretending to be that vendor to redirect an in-progress payment to an account the fraudster controls.
How a Lookalike Domain Is Built
Common techniques include swapping a letter for a visually similar one, adding or removing a hyphen, changing the top-level ending, or inserting an extra character that's easy to miss at normal reading speed.
Attackers often register these domains well before using them, sometimes months in advance, and monitor a target business's public communications or a compromised mailbox to time the fraudulent email convincingly.
The email itself frequently mirrors a real, ongoing conversation thread, referencing actual invoice numbers or project details, which is part of why it can bypass a recipient's normal scepticism.
Why a Quick Glance Isn't Enough
Most people read email addresses quickly and recognise the overall shape rather than checking every character, which is exactly the gap a lookalike domain is designed to exploit.
Mobile email clients often truncate or hide the full sender address by default, showing only a display name, which makes a lookalike domain even harder to catch on a phone than on a desktop.
The fix isn't reading more carefully under pressure — it's building a habit of checking the full sender domain specifically whenever an email involves a payment or bank detail change.
Practical Defences That Don't Need New Software
Verifying any payment or bank detail change over a second channel, using contact details from prior records rather than the email itself, catches this fraud regardless of how convincing the domain looks.
A business can register close variants of its own domain, or at minimum monitor for them, to reduce the chance of its own name being used to target its customers and vendors.
Email security settings that flag messages from newly registered or look-alike domains add a technical layer, but the verification habit remains the more reliable control for most small and mid-sized businesses.
Key Takeaways
- Lookalike domains are built to survive a quick visual check, often exploiting how mobile email clients hide the full sender address.
- Fraudulent emails using this technique frequently reference real, in-progress transactions to appear legitimate.
- Verifying payment and bank changes over a second, independently sourced channel defeats this fraud regardless of how convincing the email looks.
Frequently Asked Questions
Q: How can we check if someone has registered a lookalike of our own domain?
A: Domain monitoring services can flag newly registered look-alike variants of a business's domain, giving an early warning before one is used against customers or vendors.
Q: What should we do if we've already sent a payment to a lookalike domain's account?
A: Contact your bank immediately to request a transfer recall and report the incident through India's National Cyber Crime Reporting Portal — acting within hours meaningfully improves the odds of recovery.
How iTechFixr Can Help
We review email security configurations for lookalike-domain detection and help finance teams build verification habits that catch this fraud regardless of how convincing the email itself looks.

Need Help With This?
Talk to Hardik directly about your organisation's cybersecurity needs — get a tailored response within 24 hours.


