Domain fraud is the registration or use of deceptive domain names that impersonate a legitimate organization (opens in new tab) through misspelling, character substitution, or top-level domain (TLD) variation to trick users into surrendering credentials, transferring funds, or downloading malware.
The term covers a family of techniques including typosquatting (opens in new tab), combosquatting (opens in new tab), homograph attacks, and cybersquatting, and it is distinct from domain hijacking, which seizes a domain the victim already owns rather than creating a new attacker-owned one.
How domain fraud works
Domain fraud campaigns begin when an attacker registers a domain (opens in new tab) the target does not control. Business email compromise can use a lookalike domain pattern (opens in new tab): an attacker impersonates an employee, swapping [email protected] (opens in new tab) for [email protected] (opens in new tab), a single substituted letter many recipients miss.
Threat groups run the same play against employees, registering victim-specific domains (opens in new tab) that combine the target's name with keywords like "okta," "sso," and "servicedesk" (for example, victimname-okta[.]com) to impersonate corporate login and helpdesk portals.
Launch follows fast. Once a newly registered phishing domain obtains a TLS certificate (opens in new tab), the site serves over HTTPS, and the attacker layers on pre-built page templates, hosting, credential-harvesting automation (opens in new tab), and adversary-in-the-middle proxies (opens in new tab) that capture session tokens and bypass MFA.
The registered domain then becomes the conversion layer for a multi-channel campaign (opens in new tab): the same lookalike that anchors a phishing email is also the destination for a scam SMS (opens in new tab), a paid search ad (opens in new tab), or the link a vishing caller (opens in new tab) reads out to a helpdesk agent.
A coordinated takedown (opens in new tab) of that infrastructure can degrade every channel at once.
Why domain fraud is hard to stop
Email authentication validates sender authorization, not domain legitimacy. SPF, DKIM, and DMARC (opens in new tab) confirm that the claimed domain authorized and signed the message and that the identifiers align; they say nothing about whether that domain should be trusted.
An attacker who registers a well-constructed lookalike can publish valid authentication records (opens in new tab) for it, so its mail passes DMARC checks on that domain.
Governance leaves a gap exactly where practitioners need coverage most. ICANN's DNS Abuse definition (opens in new tab) covers botnets, malware, pharming, phishing, and spam, but explicitly excludes cybersquatting, typosquatting, trademark infringement (opens in new tab), and domain spoofing (opens in new tab). That exclusion drew an International Trademark Association objection (opens in new tab), but in practice, ICANN's contractual enforcement does not reach the most common domain fraud techniques.
The economics favor attackers (opens in new tab). Registrars sell cheap, disposable domains in bulk through registrar APIs (opens in new tab), and GDPR-driven WHOIS redaction (opens in new tab) obscures who registered them while registrar takedown requests (opens in new tab) drag on. When one domain comes down, attackers register a fresh batch, so the cost of losing domains to takedowns stays negligible (opens in new tab).
Types of domain fraud
Several registration techniques fall under the domain fraud umbrella:
- Typosquatting registers misspelled domain variants (opens in new tab), typically one edit away: missing letters, adjacent-key typos, transposed characters, or a wrong TLD, such as whatsalpp[.]com for whatsapp[.]com.
- Combosquatting joins a real trademark (opens in new tab) with an extra word like "support," "login," or "payment." The resulting domains read as official customer portals and rank among the most common (opens in new tab) domain fraud techniques.
- Homoglyph and IDN homograph attacks substitute visually identical characters (opens in new tab) from other scripts, such as replacing the Latin "a" in apple.com with the Cyrillic "а," so the fake looks like the real domain on screen.
- Cybersquatting is the parent legal category: the bad-faith registration (opens in new tab) of another party's trademark in a domain name. Trademark owners primarily challenge these registrations through the UDRP administrative process (opens in new tab).
- Doppelganger domains drop the dot (opens in new tab) from a fully qualified domain name: if a company uses mail.company.com, the attacker registers mailcompany.com and passively collects the misdirected email.
- Bitsquatting registers binary-bit variants (opens in new tab) of the target, such as micposoft[.]com, catching traffic from hardware-level bit-flip errors during DNS lookups.
- Level-squatting embeds the legitimate domain as a subdomain of an attacker-controlled domain (for example, www.williams.com.anotherdomain.com (opens in new tab)), exploiting users who read only the leftmost part of a URL.
How to defend against domain fraud
Effective programs layer controls because each addresses a different part of domain fraud:
- Enforce email authentication, and know its limits. Publish DMARC at p=reject where possible and SPF "-all" on domains that send no mail, following M3AAWG best practices (opens in new tab). This stops attackers from spoofing your own domains, though it does nothing against lookalikes registered elsewhere.
- Monitor new registrations and certificate transparency logs. Watch new domain registrations (opens in new tab) and the public TLS certificates (opens in new tab) that certificate authorities log at issuance; a freshly certificated lookalike is a strong pre-attack signal. Where feasible, defensively register high-probability variants, following NIST guidance (opens in new tab).
- Harden your own registrations. Apply registrar or registry locks (opens in new tab) and require MFA on registrar portals, and use unique EPP authInfo (opens in new tab) per domain rather than one code across an account.
- Run takedowns against the registrar and the hosting provider. Hosting providers can pull individual phishing pages (opens in new tab), but stopping resolution entirely (opens in new tab) requires the registrar or registry. For trademark-based disputes, the UDRP process (opens in new tab) offers transfer or cancellation.
These monitoring and takedown layers only hold at scale when they run continuously and automatically.
How Doppel helps
Doppel, the AI-native Social Engineering Defense (SED) (opens in new tab) platform that unifies Digital Risk Protection (DRP) (opens in new tab) and Human Risk Management (HRM) (opens in new tab), automates this monitoring and enforcement loop (opens in new tab). It detects lookalike domains as they register and moves them into takedown workflows before campaigns reach customers.
Each fraudulent domain is one node in a broader impersonation campaign spanning fake social profiles, scam ads, SMS lures, and phishing pages; the Doppel Threat Graph (opens in new tab) correlates those signals into a single campaign view (opens in new tab) behind each lookalike.
Agentic AI (opens in new tab) then correlates, prioritizes, and executes takedowns across registrars, hosts, social platforms, and ad networks, while analysts focus on the escalations that need human judgment.
The same agentic AI can convert a detected threat into an employee simulation (opens in new tab) with one click, so the tactics targeting your brand externally train your workforce internally. The objective is to raise the price of impersonating your brand until attackers judge it too costly to attack.
A guided demo shows Doppel mapping and dismantling the domain infrastructure aimed at your brand across domains, social, ads, and messaging channels. Request a demo (opens in new tab) to get started.
Frequently asked questions about domain fraud
What is domain fraud?
Domain fraud is the deliberate registration or use of domain names that impersonate a legitimate organization through tactics like misspellings, lookalike characters, or alternate top-level domains. Attackers use these deceptive domains to harvest credentials, redirect payments, or distribute malware. The term is an umbrella covering typosquatting, combosquatting, homograph attacks, cybersquatting, and related registration techniques.
What is the difference between domain fraud and domain hijacking?
Domain fraud creates new deceptive infrastructure: the attacker registers and owns a domain that resembles a legitimate one. Domain hijacking compromises existing infrastructure: the attacker takes control of a victim-owned domain by breaching a registrar account or manipulating DNS configuration. Attacker-registered deceptive domains map to technique T1583.001 (opens in new tab) in MITRE ATT&CK, while compromised existing domains (opens in new tab) map to T1584.001. The defenses differ accordingly: registration monitoring and takedowns for fraud, and registrar locks (opens in new tab) for hijacking.
What is an example of domain fraud?
The Smishing Triad operation (opens in new tab) rotated a large pool of active phishing domains, sending toll-payment lures over iMessage and RCS that funneled victims to lookalike payment pages. Those deceptive registrations were the conversion layer of a wider impersonation campaign (opens in new tab), moving victims from messaging lures to payment pages.
How do I report a fraudulent domain impersonating my company?
Report it to the domain's registrar and its hosting provider simultaneously, identifying both abuse contacts and attaching evidence such as screenshots of the fraudulent page or phishing email headers. You can also report through the Anti-Phishing Working Group (opens in new tab) and, in the United States, file with the FBI's IC3 (opens in new tab). If an ICANN-accredited registrar fails to act on a well-evidenced abuse report, escalate to ICANN Contractual Compliance (opens in new tab). For trademark-based disputes, the Uniform Domain Name Dispute Resolution Policy (UDRP) offers a domain dispute proceeding (opens in new tab) that can transfer or cancel the domain.
