DMARC Engine
Home/Free tools/Lookalike Domain Checker
Free tool · Security & threat analysis

Lookalike Domain Checker

Find registered lookalike variations of your domain.

Enter your domain to generate the lookalike variants a scammer would register to impersonate you, then see which ones are already taken. We check each candidate live against DNS. Nothing is stored.

The Lookalike Domain Checker searches for registered domains that visually or typographically resemble your own. It generates common deception patterns: character swaps (rn for m), inserted or dropped letters, alternative top-level domains (.co, .net, .biz), hyphenation and homoglyphs (Unicode characters that look like Latin letters). It then checks which of those variants actually exist in DNS or the registry. The result is a shortlist of domains an attacker could plausibly use to impersonate your brand.

Why lookalike domains matter

Email authentication protects the exact domain you control. A correctly configured DMARC policy at p=reject stops criminals from spoofing your real domain, so they often register a near-identical one instead and send phishing or invoice-fraud messages that pass their own SPF and DKIM. Because the sending domain is genuinely theirs, authentication checks succeed and the message looks legitimate to recipients who do not read the address carefully.

How to read and act on the result

Each listed variant is a candidate for monitoring or defensive action. Prioritise domains that already resolve, have active MX records, or sit on the same registrar tiers attackers favour.

  • Defensively register the closest high-risk variants you can afford, especially common TLD swaps.
  • Monitor the rest for new registrations and changes to MX or web content.
  • Report domains used in active phishing to the registrar and relevant authorities.

Lock down your real domain first (see how to reach DMARC enforcement), then watch the perimeter. Our done-for-you service includes ongoing lookalike monitoring for the domains we manage.

Frequently asked questions

What is a homoglyph attack?

A homoglyph attack uses Unicode characters that look identical or near-identical to Latin letters (for example the Cyrillic а in place of the Latin a) to register a domain that appears the same to the human eye but is technically different. These internationalised (IDN) lookalikes are particularly dangerous because the deception is invisible in many fonts.

Can DMARC stop a lookalike domain?

No. DMARC, SPF and DKIM only authenticate the exact domain you publish records for. A lookalike domain is a different domain that the attacker owns, so they can configure their own valid authentication. You stop lookalikes through monitoring, defensive registration and takedown requests, not through DNS records on your domain.

Should I register every variation this tool finds?

Registering everything is rarely practical or affordable. Focus on the highest-risk variants: common TLD swaps of your exact brand, single-character typos that map to nearby keys, and any homoglyph that is indistinguishable at a glance. Monitor the remainder instead.

A lookalike domain is already sending phishing. What do I do?

Gather evidence (email headers, screenshots, URLs), then report it to the domain's registrar and hosting provider via their abuse contact, and to anti-phishing services. Warn your customers and staff. Confirming your own domain is at DMARC enforcement ensures attackers cannot also spoof your real address.

Does this tool guarantee it finds every lookalike?

No automated generator can enumerate every possible variation, and new domains are registered constantly. The checker covers the most common and effective deception patterns, but you should treat it as a recurring monitoring task rather than a one-off scan.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.