Skip to content
All field notes

Lookalike Domains & BEC: Why DMARC on Your Real Domain Is Not the Whole Story

DMARC stops attackers forging your exact domain — not one that looks like it. How lookalike domains and display-name tricks drive business email compromise, and how to defend the gap.

PlatOps Security TeamEmail security4 min read
The short version
DMARC stops exact-domain spoofing. It does NOT stop lookalike domains (rnicrosoft.com) or display-name impersonation — and those drive most business email compromise.
Enforced DMARC is necessary but not sufficient: it closes the easiest attack, which pushes attackers to the next one.
Close the gap with a layered defense: lookalike-domain monitoring, user training on display-name tricks, and trust signals like BIMI.
Treat exact-domain protection as the floor, then defend the cousins.

You enforced DMARC. Exact-domain spoofing of yourcompany.com is dead — receivers reject it. So you are protected against impersonation, right?

Not quite. The attacker does not need to forge your domain when they can simply register one that looks like it. yourcompany.com is locked down; yourcompany-billing.com and yourcornpany.com are a $10 registration away — and DMARC has nothing to say about either, because they are not your domain. This is the gap that powers most business email compromise (BEC), and closing it takes more than authentication.

What DMARC does — and does not — stop

DMARC's protection is precise and worth stating exactly, because overestimating it is how teams get blindsided:

  • It stops exact-domain spoofing. Mail with your real domain in the From: that is not authenticated and aligned gets quarantined or rejected. This is real, valuable protection — and the single most common impersonation method.
  • It does nothing about a different domain. A lookalike like rnicrosoft.com (r-n reading as "m") or yourcompany.co instead of .com is a domain the attacker owns. They can publish perfect SPF, DKIM, and DMARC on it. It passes every check — because it is legitimately theirs.
  • It does nothing about the display name. Mail from accounts@gmail.com with the display name "Your CEO" passes its own authentication. DMARC never sees a violation; the recipient sees a trusted name.

So enforced DMARC does not fail here — it is simply not the control for this threat. It closes the easy door, which is exactly why attackers walk to the next one. (If you are still getting exact-domain protection in place, start with what DMARC is.)

How BEC actually uses the gap

Business email compromise rarely involves forging your domain at all. The common patterns:

  • Cousin domains. Register a confusable domain, authenticate it properly, and email your finance team a "urgent wire change" from cfo@yourcompany-corp.com. It looks right, and it passes DMARC — its own.
  • Display-name spoofing. From a throwaway mailbox, set the display name to a real executive. On mobile especially, recipients see only the name, not the address.
  • Reply-chain and lookalike combos. Spin up a lookalike, mirror a real thread, and insert a fraudulent request mid-conversation.

None of these trip DMARC, because none forge your actual domain. They exploit human trust, not protocol gaps.

Closing the gap: defense in layers

Since no single control stops BEC, you stack them:

  • Enforce DMARC first. It is still the floor — it removes the easiest method and forces attackers into noisier, more detectable ones. Do not skip it.
  • Monitor for lookalike registrations. Watch for newly registered domains that resemble yours (character swaps, added words, alternate TLDs). Catching a cousin domain early lets you warn staff or pursue takedown before it is used.
  • Train for the display-name trap. Teach staff to check the full address, to treat payment/credential changes as out-of-band-verify events, and to distrust urgency. This is the highest-leverage defense against the human-targeted attacks DMARC cannot see.
  • Add visible trust signals. BIMI displays your verified logo on authenticated mail in supporting clients — which both reinforces your real mail and makes its absence on a lookalike more noticeable. It builds on enforced DMARC, so it is a natural next step.

A realistic mental model

Picture two layers. DMARC governs your domain — lock it to p=reject and it is solid. Everything resembling your domain lives outside DMARC's reach, in the territory of monitoring, training, and trust signals. Mature email security treats DMARC as the non-negotiable base and then deliberately defends the cousins.

DMARC is the foundation, not the finish line. Get to enforcement so your real domain cannot be forged, then defend the space DMARC does not reach — the cousins, the display names, the human in a hurry. Confirm your domain is actually enforcing, then build the layers on top.

Questions we get asked

No. DMARC only protects your exact domain. It stops attackers from forging mail that claims to be from yourdomain.com, but it does nothing about a separate domain an attacker registers to resemble yours — like yourdoma1n.com or yourdomain-support.com. Those are different domains the attacker controls, so they can authenticate them perfectly. Defending against lookalikes needs monitoring and user awareness, not DMARC.

Field notes, twice a month.

When a mailbox provider changes the rules, you hear it here with the record you need to change. No digest, no roundup, no product news.

DMARC field notes, twice a month, from PlatOps Security, LLC (Bethesda, MD). We use your address only to send it. Unsubscribe with one click in any issue. Privacy policy.