Impersonation
Someone registered a domain that looks like yours. What can you actually do?
A customer forwards you an email. Your logo, your tone, your invoice layout. The
address it came from is not yours — it is one letter off, or it has a word bolted onto
the end. acme-billing.com. acrne.com. acme-support.net.
The first instinct is that this has to come down today. The honest answer is that it probably will not, and that the things which actually protect your customers are not the takedown. Here is the order that works.
First: was the domain even used?
Before anything else, get the raw headers of the email your customer forwarded, not the forwarded copy. In most mail clients this is “Show original” or “View source”.
You are looking for two fields:
Return-Path:— where the mail actually came from.Authentication-Results:— whether SPF, DKIM and DMARC passed, and for which domain.
This matters more than it sounds. Most impersonation never touches a domain at all: the
sender sets the display name to “Acme Billing” and sends from a free mailbox. The
lookalike domain is in the text of the mail, not in the envelope. If Return-Path points
somewhere unrelated, the domain you are worried about has not been used to send anything
yet — and your response is completely different.
If the mail genuinely came from the lookalike domain, Authentication-Results will show
it passing SPF for that name. That means someone configured it properly, which means
this is not a squatter sitting on an asset. It is being operated.
Then: what is the domain set up to do?
Four commands. None of them touch the other party.
# Who registered it, and when
whois acme-billing.com | grep -i 'registrar\|creation\|updated'
# Is it pointed at anything?
dig +short acme-billing.com A
# Can it send mail as itself?
dig +short acme-billing.com MX
dig +short acme-billing.com TXT | grep -i spf
Then search the name on a certificate transparency log viewer such as crt.sh to see
whether anyone has been issued a certificate for it.
Read the results like this:
- No A record, no MX, no certificate. Parked. Registered and left. Annoying, low urgency, and the least likely thing anyone will act on for you.
- A record, certificate, no MX. There is a page. Go and look at it — carefully, and not from a machine you care about. If it is a copy of your login page, you have something concrete to report, and the next section moves fast.
- MX records configured. This is the loud one. Nobody sets up mail on a domain they bought to resell. A lookalike with working MX is being prepared to send mail as you, or is already doing it. Treat this as the urgent case regardless of what the page shows.
The creation date tells you how long you have been exposed without knowing.
The four things you can actually do
| What | How long | What it needs | What it gets you |
|---|---|---|---|
| Tell your own customers | Hours | Nothing | Most of the real protection |
| Report the page for phishing | Hours to a day | A live copy of your site | Browser warnings for everyone |
| Report to the registrar or host | Days, often never | Demonstrated abuse, not similarity | Suspension, sometimes |
| File a UDRP or URS | Two months and up | A trademark and four figures | The domain, eventually |
They are in that order deliberately. The fastest and most effective thing on the list is the one that does not involve anyone else’s cooperation.
Tell your customers first
Before you file anything, send a short note to the people who could receive the fake mail. Name the real domain you send from. Say what you will never ask for. Keep it to four sentences — a long security advisory gets skimmed, and this only works if it is read.
This is the only step that is entirely inside your control, works immediately, and protects people whether or not the domain ever comes down. Everything below is slower and less certain.
Report the page, not the domain
If there is a live copy of your site, report the URL to the browser blocklists — Google Safe Browsing and Microsoft SmartScreen both take public reports, and the APWG accepts phishing submissions that propagate widely.
This is underused and it is the highest-leverage fast action available. A flagged URL throws a full-page red interstitial in Chrome, Edge, Firefox and Safari, often within hours. The domain still exists and still belongs to whoever bought it. Practically nobody will reach it.
Report to the registrar and the host
Every ICANN-accredited registrar publishes an abuse contact and is obliged to act on DNS abuse — phishing, malware, botnets. Send the evidence: the URL, a screenshot, the mail headers, timestamps.
Here is the part most guides leave out. Registrars act on demonstrated abuse, not on resemblance. A domain that merely looks like yours and is sitting parked is not abuse under any policy they are bound by, and a report that says “this is confusingly similar to our brand” will be closed. If you have live phishing, say so in the first line and attach proof. If you do not, the registrar is not the right lever.
The hosting provider or CDN is often faster than the registrar, because the content itself violates their terms rather than requiring a policy judgement about names.
UDRP, and its cheaper sibling
The UDRP is the formal route to take ownership of the domain. It works. It is also slow and gated:
- You need trademark rights — registered, or demonstrable common-law rights in the name. Without them the complaint fails on the first element.
- WIPO’s filing fee is US$1,500 for a single-panelist case covering up to five domains, before your lawyer has charged you anything.
- Expect roughly two months from filing to decision.
The URS is faster and cheaper, around US$375, but it only suspends the domain for
the remainder of its registration term — you do not get it — and it requires clear and
convincing evidence rather than the balance of probabilities. It also does not cover
.com or .net, which is where most lookalikes live.
Both are worth it for a domain being actively used against you. Neither is worth it for a parked typo, and that is the great majority of what gets registered.
What usually happens
Nothing.
WIPO handles a few thousand UDRP cases a year. Several hundred thousand domains are registered every day. The arithmetic does not leave room for the idea that lookalikes get dealt with — the overwhelming majority are never contested, never suspended, and simply sit there.
That is not a reason to do nothing. It is a reason to be clear about which actions depend on someone else deciding to help you, and which do not.
Two things not to do
Do not write to the registrant. If the domain is parked and unused, a message from you is the signal that it is worth something. You have just told them who to price it for.
Do not buy it, usually. A genuine typo of your own name that you should have registered years ago is worth the eight dollars. A domain someone bought specifically to lean on you is not — paying marks you as a company that pays, and the next one appears a week later. You also cannot defensively register your way out of this: the space of names that look like yours is effectively unbounded.
What you actually control
You cannot control whether someone registers a name that looks like yours. You cannot reliably control whether it comes down. Both of those belong to other people.
What you control is how long it takes you to find out.
Every option above gets better the earlier you reach it. Browser blocklists are most effective before the campaign is sent, not after. A registrar report lands harder when the phishing page is fresh and live. A note to your customers is worth a great deal on the morning the domain appears and very little the week after they were already caught. The customer forwarding you an email is the worst possible way to start this, because by then every clock has been running for a while.
So the thing worth building is not a takedown process. It is a shorter gap between the registration and you knowing about it.
All of the above is doable by hand: the headers, the four commands, the certificate search, the reports. What is not doable by hand is running it every morning, against every name that could be mistaken for yours, across every place a domain can be registered — which is the only version of this that gets you there before the mail does.