Attackers don’t always try to break into your systems. Sometimes they just build a fake version of your brand.
They register a domain that looks almost exactly like yours. Add a convincing logo. Set up email. Then start sending messages to your customers, partners, or employees. Nobody hacked anything. They just made something that looks close enough to fool people who aren’t paying close attention.
It’s a real problem, and domain monitoring is how you catch them doing it.
What is domain monitoring?
Domain monitoring is the practice of watching for newly registered domains that closely resemble yours.
When a new domain gets registered anywhere in the world, that registration is publicly logged. Domain monitoring services scan those logs continuously, flagging domains that look like potential impersonators of your brand. You get an alert. You can investigate, take action, or file a takedown request.
Domain monitoring means two different things depending on who you ask, though:
- Tracking your own domain’s renewal dates and sending expiry alerts (useful, but not what we’re talking about here).
- Watching for lookalike domains being registered by people who are not you.
The latter is what we’re focusing on here.
What domain monitoring watches for
Not all lookalike domains look the same. Attackers tend to follow patterns like:
- Typosquatting. Simple misspellings of your domain. Think gooogle.com or swapping a letter for an adjacent one on the keyboard. These work because people mistype, and a close-enough domain can catch someone on autopilot.
- Combosquatting. Your brand name combined with an extra word. login-valimail.com, valimail-security.com, valimail-support.net. These feel plausible because they look like subdomains or internal tools.
- Different TLDs. Same name, different extension. If your brand lives on .com, attackers might grab .net, .co, .org, or a newer TLD like .io or .ai. The more your brand grows, the more variations become worth registering.
- Homograph attacks. Unicode characters that look identical to standard Latin letters can be used to create domains that are visually indistinguishable from the real thing. An “a” that’s actually a Cyrillic “a.” A domain that passes a glance and fails a copy-paste.
- Subdomain-style variations. Domains structured to look like subdomains of your real domain. valimail.com.phishing-site.net is not a subdomain of valimail.com, but it looks like it could be to someone skimming an email.
Why this matters for your business
When someone gets phished using a domain that resembles yours, they don’t necessarily blame the attacker. They blame you. Your brand, your reputation, your customer relationship—all of it takes a hit for something you didn’t do and technically couldn’t control.
The practical damage is real, too. Customers lose money or credentials. Partners get targeted through your supply chain relationships. Employees get socially engineered using your own brand against them. And if it makes the news, explaining that someone registered a fake domain is cold comfort to anyone who got hurt.
Most organizations don’t find out a lookalike domain is being used against them until someone reports it. A customer emails asking why you’re requesting their password. A partner flags a suspicious invoice. By then, the campaign has already been running.
Domain monitoring gets you in front of it.
Domain monitoring vs. DMARC: What’s the difference?
DMARC is an email authentication protocol that stops attackers from sending email that appears to come directly from your domain. If your DMARC policy is at p=reject, any email claiming to be from you@yourdomain.com that fails authentication gets blocked before it reaches the recipient.
That’s important. But it doesn’t cover lookalike domains.
Ultimately, DMARC only governs your domain. If an attacker registers your-domain.com or yourd0main.com, sets up their own SPF and DKIM records, and sends phishing email from that address, DMARC has nothing to say about it. The attacker isn’t spoofing your domain. They’re using a different one that happens to look similar. Their email passes DMARC authentication just fine.
DMARC and domain monitoring address different attack vectors. You need both:
- DMARC prevents direct impersonation of your domain
- Domain monitoring catches the lookalike registrations that DMARC can’t touch
How to act on your domain monitoring findings
Finding a suspicious domain is step one. Knowing what to do with it is step two.
Not every alert is worth the same level of urgency. A domain registered six months ago that hasn’t appeared in any email traffic is different from one registered last week that’s already redirecting to a fake login page.
Triage matters.
Once you’ve identified an active threat, you have options:
- You can request a takedown through the domain registrar, especially if the domain is clearly impersonating your brand.
- You can file an abuse report with the registrar or relevant hosting provider.
- You can submit a complaint through ICANN’s Uniform Domain-Name Dispute-Resolution Policy (UDRP).
You can also play defense proactively. Registering high-risk variations of your own domain before attackers do removes the opportunity entirely. No, it’s not cheap at scale, but for your most critical variations, it’s worth it.
For the full takedown playbook, see our guide on how to take down lookalike domains targeting your business.
Valimail’s Domain Lookalike Finder scans for domains that resemble yours and surfaces them before they show up in a phishing campaign. It’s a solid place to start if you want to see what’s already out there.
Invest in a domain monitoring service sooner rather than later
Hindsight is 20-20. But your brand can do better than that.
Once you know what’s out there, you can do something about it. Check your domain to see your current authentication status, or sign up for Valimail Monitor to get continuous visibility into who’s sending email as your domain and what lookalike threats might already be in play.
Both are free to start. Which, given what’s at stake, is a more-than-reasonable trade.
Frequently asked questions
What’s the difference between domain monitoring and DMARC?
DMARC prevents attackers from spoofing your actual domain in email. Domain monitoring watches for lookalike domains that attackers register separately. They address different threat vectors and work best together.
Can I do domain monitoring manually?
Technically, yes. You can check domain registration databases, set up Google Alerts, and monitor brand mentions. In practice, it doesn’t scale. The number of possible variations of most domain names, across hundreds of TLDs, makes manual monitoring a part-time job with no guarantee of catching everything. Automated monitoring exists for a reason.
What happens if someone registers a domain that looks like mine?
Registration alone doesn’t mean active harm. Some are defensive registrations by other companies, some are parked, some are sitting idle. The risk escalates when the domain is actively used in phishing email, pointed at a fake website, or showing up in brand abuse reports. Domain monitoring tells you a suspicious domain exists, but investigation tells you whether it’s an active threat.