Two ways a stranger sends email that looks like it came from you: register a domain one letter off yours, or send from your exact domain because your mail rules allow it. We read both from public registration and DNS records, and write the fix step for your IT provider.
Two public records, read the way anyone could read them: the domains registered near yours, and the DNS records that say who may send email in your name.
Sample findings, as they appear in Technical Evidence and Findings. Values are illustrative and labelled Sample.
Registered domains near yours, read from public registration and DNS records.
Your SPF, DKIM and DMARC records, and what they let a stranger do, in plain words.
The one-line check anyone can run to see whether a lookalike is registered, so you can confirm the finding yourself.
What your IT provider does: publish or tighten the DMARC record, and warn staff and clients that the lookalike exists.
Five steps, from the first read to the daily re-check.
We read five things: whether email in your firm's name can be forged (SPF, DKIM, DMARC), which staff addresses appear in monitored breach databases, lookalike domains, what your own website and mail setup advertise, and what AI assistants say about your firm.
Lookalike registrations and your mail rules, read at audit and re-read daily under monitoring.
Firms whose clients act on an email that looks like it came from the firm.
Lookalike domains and whether email in your name can be forged, with the fix step for your IT provider. Three documents and a signed summary inside 72 hours of confirmation.
Request your firm's briefWe would like to use Google Analytics to count visits and see which pages are read. It stays off unless you accept. Cookie policy