Payment-redirection fraud
The classic: a lookalike domain sends “updated” bank details at the moment money is about to move. The email looks right because the domain almost is.
Business email fraud almost always starts with a lookalike domain — something that reads like you, used to slip a fake invoice or payment change into a real conversation. Enter your domain and we’ll check public records for the common impersonation patterns, and show which already exist and which can send email as you.
Type your domain below — just the domain, like yourcompany.co.uk. This instant check looks up up to 60 of the most common impersonation patterns — lookalike spellings, missing letters and swapped domain endings — in public DNS. It’s a fast first look; for the complete picture, the free emailed report runs a far deeper scan across hundreds of variations. No sign-up, and we don’t store your domain unless you ask for the report.
Lookalike domains sidestep your defences entirely — they don’t break in, they just pretend to be you to someone who trusts you.
The classic: a lookalike domain sends “updated” bank details at the moment money is about to move. The email looks right because the domain almost is.
It isn’t only your domain. Attackers impersonate your suppliers to you, and you to your clients — which is why monitoring the whole chain matters.
Email authentication so spoofed mail is rejected, monitoring for new lookalikes, and a finance-team verification habit. Read more on our cybersecurity and legal-sector pages.
Business Email Compromise — the most damaging attack on SMEs — almost always starts with a lookalike domain: something registered to read like you (or a supplier), then used to slip fake invoices or payment-change requests into a real conversation. This tool generates common impersonation variations of your domain (different endings, added words like ‘-accounts’, typos, look-alike spellings) and checks, via public DNS, which ones are actually registered and which have email configured.
No — and we’re careful to say so. A registered lookalike might be an unrelated business, a parked domain, or one you registered yourself defensively. What matters is the mail-capable ones: a lookalike with email set up can send messages designed to look like they come from you. Those are worth investigating, which is what the report and a conversation with us are for.
Unlike some of our other tools, this one has to send your domain to our server — DNS lookups can’t happen in your browser. But your domain (which is public information anyway) isn’t stored: we look it up and return the result. Nothing is kept unless you choose to enter your email to have the report sent to you.
It’s a fast, free sample — it checks a set of the most common impersonation patterns, not every possible variation, and it’s a point-in-time snapshot. Attackers register new domains constantly, so a clean result today isn’t a guarantee tomorrow. That’s why our managed clients get continuous monitoring that watches for new impersonation domains as they appear — it’s included as standard in the NorthMSP Standard — alongside email authentication (SPF, DKIM, DMARC) so spoofed mail gets rejected.
The practical fixes are well understood: lock down email authentication so mail from lookalikes is rejected, set up monitoring so new impersonation domains are caught early, brief the finance team on verifying payment changes, and keep a response plan ready. It’s exactly the work our cybersecurity and Microsoft 365 services cover — book a free health check and we’ll look at it properly.
Email authentication so spoofed mail is rejected, monitoring for new impersonation domains, and a finance-team verification habit. We’ll look at all of it properly.