DMARCify logoDMARCify
Playbook

DMARC will not stop lookalike domains — here is the control that does

DMARC protects the domains you own from direct spoofing. It cannot stop an attacker registering a similar domain. Use ownership controls, monitoring, and recipient-side defenses to cover both threats. · 6 min read · by DMARCify team

Editorial illustration of authenticated and lookalike-domain emails taking separate paths around a central security shield.
Field note

DMARC is a strong anti-spoofing control for a domain you own. Treat lookalikes as a separate brand-abuse problem: reduce the available names, watch for registrations, and give recipients a way to verify urgent requests.

DMARC is excellent at one specific job: it lets a domain owner publish how receivers should handle mail that claims to be from that domain but cannot authenticate and align. It does not grant ownership over names that merely resemble yours. An attacker can register a different domain, authenticate mail from it perfectly, and still use a name designed to be read as your brand.

Why a lookalike can pass DMARC

DMARC evaluates the domain in the visible From address, called the author domain, against authenticated SPF or DKIM identifiers. That is why it is effective when somebody sends ceo@your-company.example without permission. The mechanism is defined in RFC 9989.

Now change the address to ceo@yourcornpany.example. That is a separate domain, not a failed use of your-company.example. If its owner configures SPF, DKIM and DMARC for that name, a receiver can see a legitimate DMARC pass for the attacker's domain. DMARC has done its job; the problem is the reader being deceived by the name.

Do not turn this limitation into an excuse to delay DMARC enforcement. Direct spoofing is common, cheap, and precisely the attack DMARC helps receivers suppress. The useful security model is two controls: enforced DMARC for names you own, plus brand-abuse controls for names you do not.

Recognize the three common variants

  • Typo variants: a missing, swapped, or duplicated letter.
  • Visual confusables: characters, scripts, or letter shapes that make a different name appear familiar.
  • Context variants: a plausible word such as -billing, -verify, or a new top-level domain appended to the brand.

The exact risk depends on how people encounter the name. A font can make two characters look alike; a mobile mail client can make the domain harder to inspect; an urgent payment or sign-in request can reduce the time a recipient spends checking it. CISA recommends using a known contact methodrather than relying on the contact details in a suspicious message.

Build a proportionate coverage plan

Start with the domains and workflows attackers value most
  • Inventory your primary brand, country domains, acquired brands, and names used for customer mail.
  • Register a small, justified set of high-risk typo and confusing variants; put non-sending names behind DMARC enforcement and a Null MX where appropriate.
  • Monitor new registrations and certificate activity for your primary name and important variants; route credible findings to one named owner.
  • Require an out-of-band check for bank-detail changes, credential requests, and other high-consequence instructions.
  • Give staff and customers a simple reporting route, then preserve the original headers and domain evidence for investigation.

Defensive registration is not a hunt for every possible spelling. It is a risk decision: focus on the variants that are easy to mistake, relevant to your audience, and likely to be used in a costly workflow. For a parked defensive domain, pair DMARC enforcement with the no-mail posture described in our parked-domain guide.

Keep ownership monitoring separate from DMARC reporting

Aggregate DMARC reports are valuable evidence about mail receivers saw using a domain you control. They will not enumerate attacker-owned lookalikes, and their absence does not prove no imitation domain exists. Keep the two data sets separate: DMARC data for authentication posture and a domain or brand-monitoring feed for lookalike discovery.

When a suspicious domain appears, record the exact domain, first-seen time, registrar or hosting evidence where available, the impersonated workflow, and any message headers. Escalate based on observed abuse and business impact. A registration by itself is a lead; a credential-harvesting page or a fraudulent invoice is an incident that may need your legal, security, and customer-support teams.

Make the verification path obvious

The strongest technical controls still need a human-friendly fallback. Publish a stable support route on your real site, use predictable sending domains, and tell customers that urgent changes to payment details or login credentials can be verified through a known channel. For internal teams, build the same rule into finance and access-management procedures rather than asking people to make a visual judgment under pressure.

That is the complementary role of DMARC: it makes the mail from your real domains easier to trust and direct impersonation harder to deliver. It does not make a lookalike real. Combining enforcement, narrow defensive ownership, monitoring, and independent verification closes the gap without promising an impossible all-domain perimeter.

Disclosure: AI tools were used in the process of creating this blog post.

More from the blog

DMARC, decoded.

The dashboard surfaces the things this post talks about — alignment, forwarders, source attribution — for every domain you monitor.

One DNS record · 60 seconds to set up