Why the usual defences fall short

Why DMARC does not stop domain lookalikes.

DMARC is one of the best things you can do for your email, and every business should have it at enforcement. It stops criminals forging your exact domain, so they cannot put your real address in the From line of a scam. That is a genuine win. It also leads a lot of people to assume they are now protected from impersonation, and that is where the misunderstanding starts, because there is one whole category of impersonation DMARC was never able to touch.

What DMARC actually protects

DMARC works on one domain: yours. When you publish a DMARC record and set it to reject, you are telling the world's inboxes to refuse any email that claims to be from your exact domain but fails authentication. That closes off direct spoofing of your address, which is exactly why it is worth doing and worth doing properly.

What it cannot touch

Your DMARC record only has authority over your own domain. A lookalike is a different domain, registered by the criminal, so your record has nothing to say about it. Worse, the criminal can publish DMARC on their lookalike and pass it perfectly, because they own it. The protection you set up on acme.com gives you no say whatsoever over acme-payments.com.

How a lookalike gets used

A lookalike domain usually takes one of these shapes:

  • A small typo, like acmecorp.com becoming acmecorp.co or acrnecorp.com.
  • An added word, such as acme-invoices.com or acme-billing.com.
  • A hidden character swap, a letter from another alphabet that looks identical to the real one.
  • A different ending, the same name on .co, .net or another domain ending.

From there the email is simple: a believable message from a domain that reads correctly at a glance, authenticated on the criminal's own record, asking for a payment or a change of details.

How to cover the gap

Keep DMARC, and add the two things it does not do. First, make sure your own domain is set up properly, so your real mail is trusted and a grade tells you exactly what to fix. Second, watch for lookalikes of your brand, so you find out the moment one is registered or starts sending, rather than after a customer or a colleague has been caught. Together those cover the impersonation DMARC cannot.

Want to see who is impersonating your domain? Check it, free.

See lookalikes of your domain that are already registered, and grade your own domain's setup, with no account. Or forward a suspicious email and we assess the sender, the domain, and whether it is a lookalike.

Check for lookalikes → Grade your domain →

Or forward a suspicious email, free →

Common questions

Does DMARC stop lookalike domains?

No. DMARC protects your exact domain from being forged in the From line. A lookalike is a different domain, so your DMARC record has no authority over it. A criminal who registers a close imitation of your domain can set up DMARC on that imitation and send from it freely.

If we have DMARC set to reject, are we protected from impersonation?

You are protected from one specific attack: someone forging your real domain. That is important and worth having at enforcement. It does nothing about a criminal using a separate domain that merely looks like yours, because you have no control over another registered domain.

What is a lookalike or cousin domain?

A domain registered to resemble a real one closely enough to fool a quick glance. It might swap a letter, add a hyphen or a word like "payments", use a character from another alphabet that looks identical, or use a different ending such as .co instead of .com. Each is a genuine, separately registered domain with its own valid authentication.

How do we defend against lookalikes then?

You need two things DMARC does not provide: authentication set up properly on your own domain, so your real mail is trusted, and active monitoring for lookalikes of your brand so you find out when one appears. Grading your domain covers the first, and watching for impersonations covers the second.