Digital Trust Hub / News / Lookalike Watch

Product update

New in Domain Trust Monitor: Lookalike Watch.

A new feature is now available in Domain Trust Monitor for Digital Trust Hub members: Lookalike Watch.

What it does

Lookalike Watch looks for domains registered to resemble yours: a swapped character, such as yourdistr1ct.org for yourdistrict.org, a missing letter, a hyphen inserted somewhere plausible, or the same name under a different ending. It checks nightly and records what it finds.

Every domain you already monitor has been added automatically, so there is nothing to set up. If you would rather a particular domain were not scanned, you can switch it off on that domain’s overview page.

Why this is worth your attention

SPF, DKIM and DMARC stop someone forging mail from your domain. They do nothing about a different domain that merely looks like yours. That domain publishes its own SPF, signs with its own DKIM, and passes DMARC perfectly, because it is authentically itself. To someone reading email on a phone, the difference is one character.

This is how business email compromise usually begins: a fake invoice, a request to change payroll direct deposit, or a vendor asking that banking details be updated before the next payment. For school districts, the money leaves through the business office rather than the help desk.

Most of what you see will not be an attack. Some near neighbors are domains you already own, and others belong to unrelated organizations that have held the name for twenty years. Expanding a row shows when the domain was registered, which usually settles the question quickly. Domains you already monitor are marked as yours automatically, and you can allowlist any lookalike you know is a false positive.

The column worth watching is Mail. A lookalike that merely resolves is typically parked. One that has picked up mail records has been set up to receive replies, which means someone intends to hold a conversation.

Informational, not a takedown service

Lookalike Watch reports what exists. It cannot prevent anyone from registering a domain, and there is no button that takes one down. It shows you the landscape; it doesn’t change it.

The most valuable use of the list is training. It gives you the real domains that could plausibly fool your own staff, for your own district, rather than generic examples from a security awareness deck. Showing your business office what these look like beside your real domain in a mail client tends to land in a way that a policy reminder does not.

Where you do decide to act, the options are blocking a specific domain at your DNS content filter and your mail gateway, and reporting genuinely malicious ones to the registrar. The control that actually prevents financial loss remains procedural: confirm any change to banking or payroll details by calling a number you already had on file, never one supplied in the message itself.

Tell us how it lands. This is new, and the Hub wants to hear whether what it surfaces is useful, whether the volume is right, and what would make it more helpful.

Open Domain Trust Monitor Share feedback