Skip to content
The DDMARC Blog

Lookalike Domains & BEC: Why DMARC on Your Real Domain Isn't the Whole Story

DMARC stops attackers forging your exact domain — not one that looks like it. How lookalike domains and display-name tricks drive business email compromise, and how to defend the gap.

PlatOps Security TeamEmail security4 min read

You enforced DMARC. Exact-domain spoofing of yourcompany.com is dead — receivers reject it. So you're protected against impersonation, right?

Not quite. The attacker doesn't need to forge your domain when they can simply register one that looks like it. yourcompany.com is locked down; yourcompany-billing.com and yourcornpany.com are a $10 registration away — and DMARC has nothing to say about either, because they're not your domain. This is the gap that powers most business email compromise (BEC), and closing it takes more than authentication.

What DMARC does — and doesn't — stop

DMARC's protection is precise and worth stating exactly, because overestimating it is how teams get blindsided:

  • It stops exact-domain spoofing. Mail with your real domain in the From: that isn't authenticated and aligned gets quarantined or rejected. This is real, valuable protection — and the single most common impersonation method.
  • It does nothing about a different domain. A lookalike like rnicrosoft.com (r-n reading as "m") or yourcompany.co instead of .com is a domain the attacker owns. They can publish perfect SPF, DKIM, and DMARC on it. It passes every check — because it's legitimately theirs.
  • It does nothing about the display name. Mail from accounts@gmail.com with the display name "Your CEO" passes its own authentication. DMARC never sees a violation; the recipient sees a trusted name.

So enforced DMARC doesn't fail here — it's simply not the control for this threat. It closes the easy door, which is exactly why attackers walk to the next one. (If you're still getting exact-domain protection in place, start with what DMARC is.)

How BEC actually uses the gap

Business email compromise rarely involves forging your domain at all. The common patterns:

  • Cousin domains. Register a confusable domain, authenticate it properly, and email your finance team a "urgent wire change" from cfo@yourcompany-corp.com. It looks right, and it passes DMARC — its own.
  • Display-name spoofing. From a throwaway mailbox, set the display name to a real executive. On mobile especially, recipients see only the name, not the address.
  • Reply-chain and lookalike combos. Spin up a lookalike, mirror a real thread, and insert a fraudulent request mid-conversation.

None of these trip DMARC, because none forge your actual domain. They exploit human trust, not protocol gaps.

Closing the gap: defense in layers

Since no single control stops BEC, you stack them:

  • Enforce DMARC first. It's still the floor — it removes the easiest method and forces attackers into noisier, more detectable ones. Don't skip it.
  • Monitor for lookalike registrations. Watch for newly registered domains that resemble yours (character swaps, added words, alternate TLDs). Catching a cousin domain early lets you warn staff or pursue takedown before it's used.
  • Train for the display-name trap. Teach staff to check the full address, to treat payment/credential changes as out-of-band-verify events, and to distrust urgency. This is the highest-leverage defense against the human-targeted attacks DMARC can't see.
  • Add visible trust signals. BIMI displays your verified logo on authenticated mail in supporting clients — which both reinforces your real mail and makes its absence on a lookalike more noticeable. It builds on enforced DMARC, so it's a natural next step.

A realistic mental model

Picture two layers. DMARC governs your domain — lock it to p=reject and it's solid. Everything resembling your domain lives outside DMARC's reach, in the territory of monitoring, training, and trust signals. Mature email security treats DMARC as the non-negotiable base and then deliberately defends the cousins.

Frequently asked questions

Does DMARC stop lookalike domains? No. DMARC only protects your exact domain. It stops attackers from forging mail that claims to be from yourdomain.com, but it does nothing about a separate domain an attacker registers to resemble yours — like yourdoma1n.com or yourdomain-support.com. Those are different domains the attacker controls, so they can authenticate them perfectly. Defending against lookalikes needs monitoring and user awareness, not DMARC.

How do I protect against business email compromise? Layer your defenses. Enforce DMARC (p=reject) to kill exact-domain spoofing, then add lookalike/cousin-domain monitoring to catch confusable registrations, train staff to check the full address rather than the display name, and use trust signals like BIMI so legitimate mail is visibly verified. No single control stops BEC — the combination does.


DMARC is the foundation, not the finish line. Get to enforcement so your real domain can't be forged, then defend the space DMARC doesn't reach — the cousins, the display names, the human in a hurry. Confirm your domain is actually enforcing, then build the layers on top.

ShareX / TwitterLinkedIn
Free to start · 14-day trial · cancel anytime

From spoofed to enforced.

p=none
5 min
p=quarantine
Week 2
p=reject
Week 4–6

Billed when your 14-day trial ends · cancel anytime before then