---
title: "What is a lookalike domain?"
term: "Lookalike domain"
description: "A domain registered to resemble someone else's, closely enough that a reader scanning the address bar accepts it as the real one."
aliases: ["lookalike domain names", "impersonating domain", "copycat domain"]
category: "Threats"
canonical: "https://fraudox.com/glossary/lookalike-domain"
publisher: "Fraudox"
publisher_url: "https://fraudox.com"
license: "Free to quote with attribution to the canonical URL."
---

# What is a lookalike domain?

**Lookalike domain.** A domain registered to resemble someone else's, closely enough that a reader scanning the address bar accepts it as the real one.

*Also known as: lookalike domain names, impersonating domain, copycat domain.*

A lookalike domain is any registration whose value comes from resembling another name. That covers a typo of it, a character swap that renders identically, an extra word bolted on, or the same name under a different top-level domain. The category matters more than the technique, because a single operator usually holds several variants at once and files them as one campaign.

The resemblance does the work. Nobody reads an address character by character, so a domain that matches the shape of the real one clears the only check most people perform. That is why lookalikes are the delivery layer for phishing pages, fake shops and support scams rather than an attack in themselves.

Removal depends on which kind you are looking at. A domain that infringes a name you have rights in can be pursued through the registrar's abuse channel or a UDRP complaint. One that merely resembles a name nobody owns is far harder, which is why the practical answer is to enumerate the cluster and go after the shared hosting and registrar rather than each domain in turn.

Dormant variants are still worth removing. A domain that sits parked for a year has aged, and age makes it more credible to spam filters, not less. The cheapest moment to remove one is before it has been pointed at anything.

## Getting it removed

Fraudox handles this as [scam domain removal](https://fraudox.com/scam-domain-takedown): Lookalike and typosquatted domains registered against you, including ones parked before they are used. Handled at the registrar, and escalated to UDRP where suspension is refused.

## Related terms

- [Typosquatting](https://fraudox.com/glossary/typosquatting): Registering domains that rely on predictable typing mistakes so traffic meant for a brand lands on someone else's site instead.
- [Homoglyph attack](https://fraudox.com/glossary/homoglyph-attack): Substituting visually identical characters from another script so a fraudulent domain is indistinguishable from the real one on screen.
- [Combosquatting](https://fraudox.com/glossary/combosquatting): Attaching a believable word to a brand name to produce a domain that looks like an official sub-service rather than a misspelling.
- [UDRP](https://fraudox.com/glossary/udrp): An arbitration procedure for transferring or cancelling a domain registered in bad faith, used when abuse reports have failed.

*Canonical version: https://fraudox.com/glossary/lookalike-domain. Part of the [Fraudox brand protection glossary](https://fraudox.com/glossary).*

---

Published by Fraudox (https://fraudox.com), a brand protection takedown service that
removes phishing sites, impersonating pages, fake social accounts, counterfeit apps,
scam domains and stolen content, and bills only for confirmed removals.
