Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-08-21By Securing Your Law Firm

What Is a Lookalike Domain? Why Your Law Firm Should Be Concerned

A lookalike domain can cost an attacker about $15 and ten minutes to register, but it can cost your firm a wire transfer. Learn how the scam works and what to check.

Blog post - By Securing Your Law Firm

Get your free Zero-Access Exposure Review™ | See Email & Sign-In Security

Registering a domain that looks almost exactly like yours can cost an attacker about $15 and take ten minutes. From there, it can be used to reroute a client's settlement funds, impersonate opposing counsel, or convince your bookkeeper to change a vendor's bank details.

No malware or breach of your systems is required. The attacker only needs a believable identity, a plausible request, and a moment when someone is moving quickly.

What a lookalike domain actually is

A lookalike domain is a web address registered by someone else and designed to be mistaken for a real one at a glance. The tricks are simple: swap a letter, add a hyphen, change `.com` to `.co`, or substitute characters that look almost identical.

For example, `securingyourlawfirm.com` might become `securing-yourlawfirm.com` or `securingyourlawflrm.com`. A person reading a message in a mail client at 4:45 on a Friday may not catch the difference.

This is often called typosquatting. When visually similar characters are substituted, it may also be called a homoglyph attack.

The detail that trips people up is that a lookalike domain is not the same as spoofing your domain. It is a real, separately registered domain. An attacker can set up valid SPF, DKIM, and DMARC records for it.

That email may pass authentication checks because the attacker owns the domain outright. Email security controls can help prevent someone from sending as your exact domain, but they cannot tell a recipient that a newly registered lookalike domain is trustworthy. That is why “our email security passed the check” is not the reassurance it sounds like.

Why this is not hypothetical

Attackers use lookalike domains anywhere a wire transfer, login credential, or trusted relationship sits at the other end of an email thread:

  • Security researchers documented a case in which the group known as Florentine Banker inserted lookalike domains into deal threads between private equity firms and startups. Across three UK-based firms, $1.3 million was wired to attacker-controlled accounts, with nearly $700,000 permanently lost.
  • A malicious browser extension distributed through an official web store sent stolen credentials to a lookalike domain made to resemble an analytics service. It drained roughly $8.5 million from users before it was caught.
  • Law firms have been targeted this way too. Holland & Knight was sued after wiring millions to a fraudulent account based on instructions that arrived through a lookalike domain associated with the actual client. We covered that case, and a similar $545,598 typosquatting loss, in our earlier post on wire fraud and email spoofing.

Researchers at Zscaler examined more than 30,000 lookalike domains over a six-month period and found that upward of 10,000 were actively malicious. Google, Microsoft, and Amazon were among the most frequently impersonated brands, alongside financial institutions and law firms handling large transactions.

The pattern is consistent: attackers do not need to break into the firm first. They can create a new identity around the firm's public name and wait for the right conversation.

Why law firms are especially exposed

Law firms sit in the middle of high-trust, high-dollar communication. Settlement disbursements, escrow instructions, real estate closings, M&A wires, and client correspondence often move through email.

A lookalike domain built to mimic your firm can put your money at risk. It can also put your clients' money at risk under your firm's name. That creates financial, relationship, reputational, and potentially professional-responsibility consequences even when your systems were never breached.

The first question is not whether an attacker could invent a lookalike domain. They can. The useful question is whether one already exists, whether your direct-domain protections are enforced, and whether your staff have a second-channel check before money moves.

What a small or mid-sized firm can do now

Enforce DMARC for your real domain

Set DMARC to `p=reject` when your legitimate sending services have been identified and aligned. A policy of `p=none` mainly reports what is happening; it does not ask receiving mail systems to reject unauthorized messages.

This closes the easier half of the problem: someone sending as your exact domain. It does not make a separately registered lookalike domain safe, so DMARC belongs alongside identity verification and domain monitoring.

Require a known-number callback for payment changes

Never approve changed wire instructions solely through the email thread that delivered them. Call a known number from your records or prior documentation, not a number included in the new message.

This control works even when the message comes from a real mailbox, passes authentication, or appears inside a familiar conversation.

Check your public lookalike exposure

Search for common variations of your firm's domain, including misspellings, hyphenated versions, changed top-level domains, and visually similar characters. Registering obvious variants may be worthwhile, but registration alone is not a monitoring program.

A one-time check tells you what is visible now. Ongoing monitoring is a separate capability for firms that want alerts when public registrations or other exposure signals change.

Review who can send as your firm

SPF, DKIM, and DMARC should reflect the services your firm actually uses. Old vendors, forgotten sending platforms, and incomplete DKIM configuration can leave direct spoofing gaps even when a policy exists.

This is a configuration question, not a badge. The goal is an enforced policy that still allows the firm's legitimate mail to arrive.

The bottom line

A lookalike domain does not hack anything. It relies on someone recognizing a familiar name and not looking twice. It works often enough that attackers keep using it.

DMARC enforcement, a known-number callback process, and visibility into newly registered lookalike domains close much of the gap. The first step is finding out what an attacker can already see about your firm.

Start with a free Zero-Access Exposure Review™

You submit two things: your firm domain and a matching work email. We send a verification link only to that work inbox, and the review runs only after you confirm that you control it.

The report is viewable through that verification link. It is not emailed. Your submitted domain is retained only during the verification window, typically up to 60 minutes; the report and scan findings are not saved, and only the requesting work email is retained for follow-up purposes.

That makes the review a practical first step for a firm that wants a clear outside-in baseline before changing email settings, registering domains, or discussing a broader engagement. Request your free Zero-Access Exposure Review™ and see what your firm's public exposure looks like now.

This article is informational and does not constitute legal or compliance advice.