Lookalike Domains: How Scammers Clone Your Website and Impersonate Your Business

A fraudulent lookalike website cloned from a legitimate business site

Someone can copy your entire website in about ten minutes. They register a domain that looks almost identical to yours, clone your pages, swap in their own phone number and email address, and start collecting whatever walks in the door.

This isn't hypothetical. We caught it happening to one of our clients recently, and the copy was so close that most people would never have questioned it.

What a Lookalike Domain Actually Looks Like

The whole attack depends on your eyes skipping over one small detail. A few of the common tricks:

  • Typosquatting. A single character off from your real domain — a dropped letter, a doubled letter, a transposed pair. Think acmeplumbing.com versus acmepumbling.com.
  • Character substitution. Swapping characters that look alike in most fonts: a lowercase L for a capital I, rn in place of m, a zero for the letter O.
  • Different extension. Your business is on .com, so they buy the .net, .org, .co, or .biz version. Nothing about that domain is a typo — it's just not you.
  • Added or hyphenated words. acmeplumbing-inc.com, acmeplumbingny.com, getacmeplumbing.com. These read as perfectly legitimate.

Once they own the domain, copying your site is trivial. Your pages are public. Your logo, your photos, your service descriptions, your testimonials — all of it is right there to be lifted.

What Happened to Our Client

The site we found was a near-exact duplicate. Same layout, same branding, same copy. Two things were different: the phone number and the email address.

That's the entire scam. Everything a visitor uses to judge whether a business is real was authentic, because it was stolen from a real business. The only parts that had been changed were the parts that route the victim to the attacker.

We can't say for certain what they intended to do with it. Sites like this typically get used to intercept prospective customers, collect deposits or payment details, harvest credentials, or lend credibility to phishing emails and invoice fraud. None of the possibilities are good.

Why Nobody Notices

Here's the uncomfortable part: a lookalike site does not appear anywhere in your own systems. It doesn't touch your network. It doesn't generate an alert in your email security. It doesn't show up in your analytics. Your firewall has no idea it exists.

Unless someone is actively watching for newly registered domains that resemble yours, the only way you find out is when a customer calls confused about a payment they made, or an invoice they never received from you. By that point the site has usually been running for months.

That's the pattern we see over and over. It isn't that these operations are sophisticated. It's that nobody is looking.

How the Takedown Works

The good news is that you have more leverage than most business owners realize. A site impersonating your business violates the terms of service of essentially every registrar and hosting provider in existence, and it's straightforward trademark and consumer-fraud territory. Providers generally do not want to host it.

The process looks like this:

  1. Document everything first. Full-page screenshots with the URL visible, timestamps, the fraudulent phone number and email, and a side-by-side against your real site. Do this before you file anything — sites like this can disappear the moment the operator senses attention.
  2. Identify the registrar and the host. A WHOIS lookup gives you the registrar. The hosting provider is often a different company, and it's worth contacting both, since either one can pull the plug.
  3. File an abuse report with each. Nearly every provider publishes an abuse contact or an online form. Be specific: state that the site is a copy of your own, cite the trademark and copyright infringement, point to the substituted contact information as evidence of fraudulent intent, and attach the documentation.
  4. Report it more broadly. Google Safe Browsing, the Anti-Phishing Working Group, and the FBI's IC3 all take reports. Browser blocklisting can neutralize a site well before the domain itself comes down.
  5. Warn your customers if there's any chance of exposure. A short, factual note beats having them learn about it from the scammer.

In our client's case, the site was down within 72 hours of our request. That's fast, but it's not unusual when the report is well documented and goes to the right place. A vague complaint sent to a generic support inbox can sit for weeks.

What You Should Be Doing Now

  • Monitor for lookalike registrations. New domains resembling yours can be watched continuously. This is the single control that turns "months undetected" into "caught in days."
  • Buy the obvious variants yourself. The common typos and the major alternate extensions cost very little per year and take the easiest options off the table.
  • Lock down your real domain. Registrar lock, registry lock where available, and MFA on the registrar account. Losing control of the actual domain is worse than anything a copycat can do.
  • Get SPF, DKIM, and DMARC right. A lookalike domain sending email as "you" is the natural next step after cloning the site.
  • Tell your team and your customers how you communicate. If everyone knows your only phone number and your only domain, a substituted one stands out.

We Watch for This

Domain impersonation monitoring is part of what we do for our clients — alongside the rest of the security stack. It's the reason we found this one before it caused real damage, and the reason it was gone in three days instead of running quietly for a year.

If you don't currently have anyone watching for this, it's worth a conversation. Give us a call at (516) 543-3170 and we'll take a look at what's out there under your name.

Let Us Handle the Tech.

Schedule a free IT, Cybersecurity & AI strategy call.

Schedule a Free Call