EASM
Domain Spoofing Detection: A 5-Signal Playbook
Andrew Mason
October 5, 2026
Domain Spoofing Detection: A 5-Signal Playbook
Summary
Domain spoofing detection needs more than DMARC. Five signals that surface lookalike domains early, how to triage them, and what gets a takedown.

Domain spoofing detection is where a lot of otherwise mature security programmes quietly fall over. You have DMARC at p=reject, SPF tidy, DKIM signing on every sending service, and you still find out about brandname-payments.co.uk because a supplier rings your finance team to ask why the bank details changed. The tooling did not fail. It was never watching the right thing.

Why DMARC enforcement is not domain spoofing detection

DMARC is an authentication control for your own domain. It tells receiving mail servers what to do when a message claims to come from a domain you own but cannot prove it. At enforcement, exact-domain spoofing stops working. That is a genuine win, and it is roughly half the problem.

Exact-domain spoofing versus a registered lookalike

An attacker who registers brand-payroll.co.uk owns that domain outright. They publish their own SPF record, sign with their own DKIM key, set their own DMARC policy if they feel like it, and every message they send authenticates cleanly. There is nothing to fail. The domain is not yours, so your policy has no reach over it, and no receiving gateway has any technical reason to reject the mail.

That is why teams with tight email security still get blindsided. They have solved impersonation of the domain and left impersonation of the brand wide open.

What DMARC aggregate reports do and do not show

RUA data is a feedback loop for domains you publish policy for. It tells you which sources are sending as you, which pass, which fail, and where your legitimate senders are misaligned. Useful for deliverability, useful for finding the shadow marketing platform nobody registered. Blind, entirely, to a domain sitting outside your DNS. If the lookalike never claims to be you at the protocol level, it never appears in a report.

Three impersonation patterns worth separating

  • Typosquats: character omission, doubling, transposition and keyboard adjacency. Cheap, high volume, often parked for advertising revenue rather than fraud.
  • Homoglyph and IDN tricks: Cyrillic characters that render identically to Latin letters in most address bars, plus the low-tech versions that survive a quick glance, rn standing in for m, uppercase I for lowercase l.
  • Combosquats: your brand plus a functional word. brand-hr-portal, brand-invoices, brandpay. These are the dangerous ones, because they are plausible to a supplier who has never memorised your real domain structure.

Combosquats deserve most of your attention. Typosquats catch fat fingers; combosquats are built to be believed.

Where ad-tech domain spoofing fits

Search for the term and you will hit a wall of programmatic advertising content, where domain spoofing means misrepresenting inventory so a bid looks like it is running on a premium publisher. Real problem, different owner. That sits with your media agency and ads.txt, not with your security team. Everything below is about criminal infrastructure built to impersonate your organisation.

The five signals that surface a spoofed domain early

1. Registration telemetry

New registrations and expiring domain drops matching permutations of your brand are the baseline feed. Watch the metadata as much as the string: the same budget registrar, the same nameserver pair and the same privacy service recurring across multiple hits usually means one operator building a set, not three unrelated coincidences. Expired domain drops matter too, because a lapsed campaign microsite you forgot about carries residual trust and inbound links.

2. Certificate transparency logs

Certificate transparency is the signal most teams underuse, and it is free. Since Chrome's CT policy took effect in April 2018, publicly trusted certificates have to be logged to be trusted by the browser, which means near real-time visibility of every hostname someone provisions TLS for. Operators almost always issue a certificate during setup, often through Let's Encrypt, before a single page of content exists.

The other advantage: CT catches subdomain abuse that permutation lists never will. brandname-login.somehostingplatform.app will not appear in any registration feed, because nobody registered a domain. It shows up in a CT log the moment the certificate is issued. Monitoring the logs directly, or via continuous DNS and certificate monitoring, is the cheapest early warning available.

3. DNS surveillance, and why MX is the highest-value record

If you track one thing, track mail records appearing on a previously parked lookalike. Content can go live hours before a phishing run starts. Mail infrastructure is typically configured days in advance, because the operator needs to warm it, test deliverability and confirm sending works before committing to a campaign.

An MX record landing on a dormant lookalike is the clearest statement of intent you will get. It buys you response time that content scraping does not. Add SPF and DKIM appearing on the same domain and you are watching someone build a sending platform for a targeted run.

4. Content and infrastructure fingerprints

Once a site is live, fingerprints cluster fakes to a single operator. Favicon hashes are unreasonably effective, because kit builders copy the icon straight from the real site. So are copied HTML structures, reused analytics or tracking identifiers, shared hosting IP ranges and identical TLS certificate serial patterns. Find one site, pivot on the fingerprint, and you frequently surface the other five domains the same crew has staged but not yet activated.

5. Criminal chatter before the infrastructure exists

Phishing kits, target lists and brand-specific access offers get traded on hacker and ransomware Telegram channels, sometimes with your brand named days before anything appears in DNS or a certificate log. Credential dumps discussed in the same places tell you which staff accounts the operator already has. This is the only signal that can precede registration entirely, which is why monitoring Telegram and closed channels for brand mentions belongs alongside the technical feeds rather than in a separate threat intelligence silo.

Building a permutation list that does not drown your team

Start from an accurate inventory of what you actually own. Not just the marketing site. Every campaign microsite, regional domain, acquisition legacy domain and defensive registration, or your sweep will flag your own forgotten estate as hostile and burn credibility in week one. Reliable external asset discovery is the foundation here, not an optional extra.

Generation rules worth running: character omission and insertion, doubled letters, transposition, keyboard adjacency, homoglyph substitution, hyphenation and de-hyphenation, plural and singular forms, alternate TLDs, and brand-plus-keyword combinations drawn from your actual business functions.

For a UK organisation, prioritise.co.uk,.uk,.com and.org.uk, then extend into the cheap gTLDs that dominate phishing registrations because they cost pennies and ask few questions. Ignore the long tail of country codes you have no presence in unless something concrete points there.

On defensive registration: buying every permutation is a losing budget line. The permutation space is effectively infinite and the registrar renewals are forever. Spend defensively where impersonation causes direct financial loss, which in practice means payroll, payments, invoicing, login and the names of your chief executive and finance director. Everything else gets monitored, not bought.

Triage: scoring what you find so the urgent cases surface first

A mid-market permutation sweep commonly returns several hundred candidate domains. Most are parked, advertising-funded or belong to an unrelated business in another sector. Only a handful will carry both live mail records and content similarity to your brand, and that small set is what deserves action this week.

Score every candidate on a consistent set of factors:

  • Mail configured: MX records, SPF, DKIM present
  • Live certificate issued, and how recently
  • Content similarity to your brand, including logos, copied pages and login forms
  • Registrant privacy or shielded WHOIS
  • Hosting reputation and whether the IP range appears in other abuse reports
  • Age of registration, with anything under 30 days weighted heavily

Then layer evidence of active targeting on top. Has the domain appeared in your mail gateway logs? In staff-reported phishing? In DMARC forensic data referencing it as a reply-to or display-name trick? A domain that has already touched your perimeter is no longer a watch item.

Treat executive-name lookalikes as a separate class. firstname-surname-consulting.com registered against a named director is not brand impersonation, it is the opening move in invoice fraud or business email compromise, and it should jump the queue. This is the argument for per-person monitoring for directors and finance staff rather than leaving them in the general brand pile.

Cadence matters more than alert volume. A daily automated sweep, a weekly review of what actually changed, and a monthly summary for management works. An unfiltered alert firehose gets muted within a fortnight, and then the one alert that mattered arrives to an empty room.

From detection to takedown: the evidence pack registrars accept

Takedowns fail on evidence quality, not on effort. A thin submission gets queued behind the well-documented ones or rejected outright, and every resubmission restarts the registrar's clock while the campaign keeps running.

Capture before you file:

  • Timestamped screenshots of the impersonating content, including any credential form
  • Full HTTP response headers and the raw page source
  • WHOIS output and current DNS records, including MX
  • Hosting provider, CDN and registrar identification with abuse contacts
  • Proof of trade mark registration or established brand ownership
  • Any phishing emails received, with full headers

Then work the chain in order: registrar abuse desk first, hosting provider and CDN in parallel, certificate authority for revocation, and submissions to Google Safe Browsing and Microsoft SmartScreen so browsers start warning your customers while the slower processes run. Interim blocking protects people days before the domain actually disappears.

Expect friction from privacy-shielded registrants, offshore registrars with a single overworked abuse inbox, and hosting providers that treat abuse reports as optional reading. Good submissions on a cooperative registrar can move within a day or two; a bulletproof host can drag on for weeks or never resolve at all.

UK-specific routes help. Nominet operates a Dispute Resolution Service for.uk registrations and suspends domains used for criminal activity on request from law enforcement. Report fraud to Action Fraud so the incident is on record, and check whether the NCSC's takedown service applies to your organisation. In parallel, block the domain at your own mail gateway and web proxy, brief your customer-facing teams with a holding statement, and keep watching the operator's registrar and nameserver pattern, because the next domain usually looks exactly like the last one.

Choosing tooling: what a domain spoofing detection capability must include

Questions worth putting to a vendor before you sign anything:

  • Do you ingest certificate transparency logs and zone file data directly, or scrape third-party aggregators on a delay?
  • How are homoglyphs and internationalised domain names normalised and matched?
  • What is the latency from registration or certificate issuance to alert in my inbox?
  • Is takedown included, billed per case, or simply out of scope?
  • Do you monitor subdomains on shared hosting platforms, or only registered domains?

Brand monitoring bolted onto an email security product tends to miss the things that are not email. Subdomain abuse, impersonating social accounts, fake mobile apps and cloned customer portals fall outside its field of view because the product was built to inspect messages, not to map what attackers can see from the outside.

Integration decides whether findings turn into work. Alerts into Slack or Microsoft Teams, tickets into Jira or your service desk, events into the SIEM, and an API so your team can automate the boring parts. An alert that lands as an email in a shared mailbox is a finding nobody owns.

Lookalike domain detection is one signal inside a wider picture. It works best next to continuous asset discovery, leaked credential triage and supplier exposure monitoring, because the same operator who registers a combosquat is often the one already holding a valid password from a third-party breach. Treat domain spoofing detection as part of external attack surface management, run the five signals continuously, and score what comes back so the handful of domains with live mail records and copied content reach a human the same day they appear.

Frequently Asked Questions

What is the difference between domain spoofing and a lookalike domain?

Domain spoofing in the email sense means forging your exact domain in the From header without owning it, which SPF, DKIM and DMARC at enforcement will block. A lookalike domain is separately registered and legitimately owned by the attacker, so it authenticates cleanly on its own infrastructure. The first is a protocol problem; the second is a brand and detection problem.

Does DMARC stop domain spoofing on its own?

Not on its own. DMARC at p=reject stops mail sent as your exact domain, and it is worth having for that reason alone. It has no effect on brand-payroll.co.uk, which publishes its own SPF and DKIM records, passes authentication and will never appear in your aggregate reports because you do not own it.

How quickly can a spoofed domain be taken down?

It varies widely. A well-evidenced report to a cooperative registrar or hosting provider can be actioned within a day or two, while privacy-shielded registrants, offshore registrars and bulletproof hosting can stretch it to weeks. Submitting to Google Safe Browsing and Microsoft SmartScreen gives customers browser-level warnings much sooner than the domain itself disappears.

Should we defensively register every lookalike domain variation?

No. The permutation space is effectively unlimited and renewals never stop, so blanket registration drains budget without closing the risk. Register defensively where impersonation causes direct financial loss, typically payroll, payments, invoicing, login and executive-name domains, and monitor the rest continuously instead.

How do certificate transparency logs help with domain spoofing detection?

Publicly trusted certificates must be logged to be accepted by modern browsers, following Chrome's CT policy taking effect in April 2018, so log monitoring gives near real-time visibility of new hostnames impersonating your brand. Operators usually provision TLS during setup, which means the certificate often appears before any content is published. CT also surfaces subdomain abuse on hosting platforms that domain permutation lists never see.

Blog Categories

All

Blog Tags

Andrew Mason

Andrew is an entrepreneur and technology leader with a strong track record of building, scaling, and exiting high-growth technology businesses. He is the founder of several award-winning companies including RandomStorm, Data Protection People, RapidSpike, Pentest People, and DarkInvader, each operating at the forefront of cybersecurity, risk management, and digital resilience. Across these ventures, Andrew has consistently focused on creating commercially successful businesses grounded in deep technical capability and clear market need.

Sign Up for Your Free Account

Unlock full visibility of your external attack surface with DarkInvader’s continuous, real-time monitoring. Create your free account to discover unknown assets, detect emerging risks and stay ahead of potential threats before attackers can exploit them.

Create My Free Account