DMARC Engine
Home/Glossary/Lookalike / cousin domain
Glossary

Lookalike / cousin domain

A domain registered to resemble a real brand's domain, used to trick recipients into trusting fraudulent email.

A lookalike or cousin domain is a domain name deliberately registered to resemble a legitimate one, so that fraudulent email appears to come from a trusted brand. Where outright spoofing forges your exact domain, a cousin domain uses a different but confusingly similar name that the attacker actually controls.

Common tricks include character swaps (rn for m), added or dropped letters (paypa1.com), alternative top-level domains (.co instead of .com), and homoglyphs from other scripts that render almost identically. Because the attacker owns the domain, they can publish valid SPF and DKIM records and even pass DMARC on their name, so authentication on your domain cannot stop them.

This makes cousin domains a favoured vehicle for phishing and business email compromise. Defence is therefore detection and takedown rather than DNS policy: monitor newly registered domains that resemble yours, defensively register the most obvious variants, and report abusive domains to registrars. Enforcing DMARC on your real domain still matters, because it forces criminals onto lookalikes you can hunt for. Use a lookalike-domain checker to enumerate permutations of your brand and see which are already registered.

Check it on your domain

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.