A quick answer for anyone trying to understand why their brand keeps showing up in phishing complaints, or why customers keep asking if a particular email is really from them.
Domain spoofing is when someone registers a domain designed to look like yours — through misspellings, different extensions, or lookalike characters — to trick customers into trusting a fraudulent site or email.
Common techniques include swapping similar-looking letters, adding or removing hyphens, using a different top-level domain, or combining your brand name with an extra word that sounds plausible.
New lookalike domains can be registered in minutes, and there's no practical limit to how many variations an attacker can try across different registrars and extensions. Manual monitoring simply can't keep pace with automated domain-generation techniques operating at scale.
By the time a customer reports a suspicious email referencing a spoofed domain, that domain may have already been used for weeks — which is why proactive monitoring matters more than reactive response alone.
Beyond the immediate risk of credential theft, spoofed domains erode customer trust in your brand over time. Customers who get burned by a convincing fake often become more suspicious of your legitimate communications too, which has a cost even beyond the direct fraud losses.
It helps for the most obvious variations, but attackers have far more combinations available than any business can practically pre-register. Ongoing monitoring and takedown is more sustainable than trying to buy your way out of the problem.
Continuous monitoring is the practical answer — scanning for new domain registrations that closely resemble yours, rather than waiting to hear about it from an affected customer.
Typosquatting is one specific technique within the broader category of domain spoofing — it refers specifically to domains based on common typing mistakes. Domain spoofing also covers other tricks, like lookalike characters or misleading extensions.