Lookalike domain
Lookalike domain (typosquat / homograph)
A domain registered to visually resemble a target domain, used for phishing, impersonation, or wire-fraud pretext.
A lookalike domain is a registrable domain visually or semantically similar to a legitimate target domain. Common patterns include single-character swaps (getleak-trace.com vs getleaktrace.com), homograph substitution using non-Latin Unicode characters (get1eaktrace.com), transposed letters (getleakrtace.com), added or dropped subdomains (secure-getleaktrace.com), and TLD substitution (getleaktrace.co vs getleaktrace.com). Attackers register lookalike domains as infrastructure for phishing kits, spoofed email pretexts, and fake login pages. Detection requires continuous monitoring of new domain registrations against permutation patterns generated from the target domain — a passive DNS + certificate-transparency + zone-file monitoring exercise. Lookalike detection alone is not sufficient; the domain must be correlated with hosting fingerprint, whois registrant, and email-authentication posture to distinguish a live attack from an inert defensive registration.
A lookalike domain against a family-office CPA, wealth-manager firm, or sports-agency principal is often the first hard signal of a pending wire-fraud attempt. LeakTrace runs continuous lookalike-domain monitoring on every advisor tenant domain plus the family office or agency principal name; new registrations are correlated with cert-transparency + hosting fingerprint and escalated inside four business hours when the pattern matches known BEC infrastructure.