Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
Cyber-intelligence glossary

Lookalike domain

Lookalike domain (typosquat / homograph)

A domain registered to visually resemble a target domain, used for phishing, impersonation, or wire-fraud pretext.

Definition

A lookalike domain is a registrable domain visually or semantically similar to a legitimate target domain. Common patterns include single-character swaps (getleak-trace.com vs getleaktrace.com), homograph substitution using non-Latin Unicode characters (get1eaktrace.com), transposed letters (getleakrtace.com), added or dropped subdomains (secure-getleaktrace.com), and TLD substitution (getleaktrace.co vs getleaktrace.com). Attackers register lookalike domains as infrastructure for phishing kits, spoofed email pretexts, and fake login pages. Detection requires continuous monitoring of new domain registrations against permutation patterns generated from the target domain — a passive DNS + certificate-transparency + zone-file monitoring exercise. Lookalike detection alone is not sufficient; the domain must be correlated with hosting fingerprint, whois registrant, and email-authentication posture to distinguish a live attack from an inert defensive registration.

Why it matters

A lookalike domain against a family-office CPA, wealth-manager firm, or sports-agency principal is often the first hard signal of a pending wire-fraud attempt. LeakTrace runs continuous lookalike-domain monitoring on every advisor tenant domain plus the family office or agency principal name; new registrations are correlated with cert-transparency + hosting fingerprint and escalated inside four business hours when the pattern matches known BEC infrastructure.

Related LeakTrace pages
Related terms
Discovery call
Mutual NDA on request. Reply within one business day.
Book at [email protected]. Full glossary at getleaktrace.com/glossary. Frequently asked questions at getleaktrace.com/faq.