How to defend the full social engineering attack chain | Register for the webinar to learn more

Research

What to Do in the First Hour After You Discover a Lookalike Domain

Spotted a lookalike domain spoofing your brand? Use this 60-minute response playbook to preserve evidence, assess risk, and start disrupting the infrastructure.

What to Do in the First Hour After You Discover a Lookalike Domain

It’s 2:15 PM on a random Thursday, and an alert pops up in your Slack channel.

Someone just registered your corporate domain with a swapped vowel or a sneaky .co extension. The site looks sleek, carries your official logos, and sits right in the path of your customers and employees.

The SOC’s collective blood pressure climbs. One person wants to click the link from a work laptop “just to see.” Another is drafting a scorched-earth email to the registrar’s abuse inbox. Legal is already looking for a meeting slot.

Take a breath. Keep the link off your work device. Then stop guessing.

A lookalike domain creates a race, but panic doesn’t make you faster. While a company debates ownership and waits on a ticket queue, an attacker can change infrastructure, launch a lure, or move to the next domain. The first hour is about preserving options: capture evidence, assess intent, warn the right people, and start disruption.

What you do in the first 60 minutes determines whether this incident ends as a quiet, neutralized non-event or a very uncomfortable conversation with your chief financial officer.

Here's your minute-by-minute playbook.

0 to 10 minutes: containment, isolation, and triage

Curiosity creates expensive unforced errors here. Your job is to gather enough evidence to judge the threat without exposing your corporate network (or your investigation) to the operator.

In the first 10 minutes, it’s all about discipline:

  • Don’t click through from a work device. Some phishing infrastructure records visitor data and uses cloaking to show different content by IP, device, or geography. Use an approved isolated environment, sandbox, or disposable virtual machine instead.
  • Preserve more than the URL. Capture full-page screenshots, timestamps, redirect chains, DNS details, certificates, and (when your process allows it) the page source. Infrastructure can change quickly, and a lonely URL in a ticket doesn’t tell the story an abuse team needs.
  • Check if it's active or parked. Is the domain actively serving a cloned version of your employee single sign-on (SSO) portal, or is it pointed to a generic parking page? A parked domain is still a serious threat, but an active clone means you're already in emergency response mode.
  • Determine the target. Figure out who the attacker is hunting. Does the domain mimic an internal HR portal (targeting employees for credential harvesting), or does it impersonate your public billing site (targeting customers for credit card fraud)?

Gathering this initial intelligence without tipping your hand is crucial. Think of it like a digital stakeout: You want to take high-resolution pictures of the getaway car, but you absolutely do not want to walk up and knock on the window.

Once you've safely preserved the raw evidence without spooking the threat actor, you can start digging into their infrastructure.

10 to 30 minutes: fingerprinting and escalation

Next, pull technical telemetry. This is where you map the attacker’s operational infrastructure and look for the telltale signs of a high-velocity campaign.

  • Pull WHOIS, registrar, and hosting info. Run a complete WHOIS query. Is the domain sitting with a cooperative registrar, or is it hosted by a bulletproof offshore entity known for ignoring abuse complaints?
  • Check the MX records. Mail infrastructure raises the stakes because the domain may be able to send or receive email. It doesn’t prove a phishing campaign is imminent, but it’s a useful escalation signal, especially when paired with a cloned login page, active redirects, or related impersonation assets.
  • Bring in legal and brand teams when trademarks, executive likenesses, or customer deception are involved. Give them the evidence package early so they can choose the right path—registrar or host abuse reports, platform escalation, trademark claims, or a UDRP complaint (opens in new tab). A DMCA notice fits copied copyrighted content; it isn’t a universal domain-takedown button.
  • Hunt for multi-channel variants. Attackers rarely register a single domain in a vacuum. Check major social channels and digital ad networks to see if the threat actor is running paid search ads or fake profiles using the exact same logos to funnel victims to the URL.

By minute 30, you should have a defensible working picture: what the domain is doing, who it appears to target, which providers sit behind it, and which signals justify escalation. “Working picture” matters. Incident response rarely hands out crystal balls.

Now, it's time to break their toys.

30 to 60 minutes: takedowns, internal defense, and drift

You’ve preserved the evidence and profiled the infrastructure. The final 30 minutes focus on execution: dismantling the setup and closing internal vulnerabilities before the attacker extracts value.

  • File coordinated takedown requests. One note to a registrar’s generic inbox isn’t a strategy. Report the abuse to the relevant registrar, hosting provider, CDN, or reverse proxy, and any platform serving the lure. Tailor the evidence to each provider’s policy and keep a clean log of submissions, case numbers, and follow-ups.
  • Alert employee and customer-facing teams in parallel. Push the domain into the appropriate security controls, then give accounts payable, support, communications, and other exposed teams the guidance they need. A takedown request doesn’t protect someone who receives the lure five minutes later.
  • Monitor for instant infrastructure reuse. Congratulations, you submitted the takedown requests. Don't pop the champagne just yet. Cybercrime syndicates operate with high levels of automation. When they realize domain #1 is dead, they instantly spin up another domain. Begin monitoring immediately for re-registrations, matching SSL certificates, and identical DNS infrastructure.

If you hit all these steps, you've successfully disrupted the immediate threat and warned your people before the trap could snap shut. But as any seasoned security pro knows, threat actors are stubbornly persistent.

Knocking down one domain may only earn you a sequel. That’s where a fully manual process starts to buckle.

The 60-minute action plan

Here’s a breakdown of how your technical objectives map out across the initial sprint:

Time window

Primary objective

Key actions

Critical escalation trigger

0 to 10 minutes

Isolation and triage

Sandbox the link, capture source code, and determine the target audience

Domain actively hosts a live clone of an internal SSO portal

10 to 30 minutes

Infrastructure fingerprinting

Execute WHOIS queries, inspect MX records, and hunt for social variants

Active MX records detected, and the domain is weaponized for outbound mail

30 to 60 minutes

Multi-tier takedowns

File abuse reports across the host/CDN, alert all teams, and track re-registrations

Threat actor actively rotates DNS or routes traffic through reverse proxies

Where manual domain response starts to buckle

Running through this checklist manually every single time a lookalike domain pops up is exhausting, stressful, and totally unscalable.

Detection without context or action leaves analysts in a reactive loop: copy registration data, rebuild evidence packages, chase providers, update tickets, repeat. Takedown timing varies by provider and case, so the real advantage comes from connecting related assets, automating repetitive work, and keeping human judgment focused on the messy exceptions.

That's why tracking malicious state changes matters. A state-change-aware system doesn't wait for an employee to report a bad link. It would have flagged the MX record activation the exact moment the attacker flipped the switch, long before your first hour fire drill even started.

You won’t remove human judgment from incident response (and you shouldn’t). You can remove a remarkable amount of copy-paste.

Doppel’s brand protection continuously monitors external channels for impersonation, including suspicious domains, cloned sites, ads, social accounts, and connected campaign infrastructure. Doppel Threat Graph then helps teams see the campaign, not just a pile of unrelated alerts.

When a malicious domain surfaces, Doppel helps gather and connect evidence, prioritize the risk, and move validated abuse into automated and expert-supported takedown workflows. You still get the audit trail. You just don’t have to make artisanal abuse reports one at a time.

Stop scrambling through emergency fire drills and permanently disrupt the adversary’s infrastructure before they even have a chance to launch.

Ready to make lookalike-domain response less manual? Schedule a demo with Doppel to see how the platform connects campaign infrastructure, accelerates takedowns, and gives your team fewer tabs to babysit.

Learn how Doppel can protect your brand from social engineering attacks

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.