You searched your company name and found a domain you don't own that looks exactly like yours. Or a client mentioned they visited a site that seemed like your business but something felt off. Or your IT person flagged a newly registered domain with your brand name in it.
This is brand impersonation — and it's more common than most business owners realise. Here's what it means, what the fraudster is likely planning to do with it, and exactly how to get it taken down.
Why Did Someone Register This Domain?
Fraudsters register lookalike domains for a few reasons, and understanding which one applies to your situation affects how urgently you need to act.
To Send Fraudulent Emails
The most common reason. They register acme-corp.com when your real domain is acmecorp.com, set up email on the fake domain, and start contacting your clients and suppliers pretending to be you — changing bank details, redirecting payments, requesting urgent wire transfers.
To Host a Fake Website
They build a site that looks like yours — same logo, same copy, same layout — to steal login credentials from your customers or sell counterfeit versions of your products.
Typosquatting
They register a domain that catches people who mistype your web address — acmcorp.com instead of acmecorp.com — and redirect them to competitors, ad pages, or malicious content.
Holding It for Ransom
Some registrations are purely opportunistic — someone registers a domain similar to yours hoping you'll pay them to hand it over. This is less common for small businesses but does happen.
Don't wait to see what they do with it. A newly registered lookalike domain that isn't yet active is still a serious threat. Fraudsters often register domains weeks before launching an attack. Act now while it's easier.
Step 1 — Document Everything First
Before you contact anyone, document the fake domain thoroughly:
- Screenshot the WHOIS record showing registration date and registrant details
- Screenshot any website content if the domain is active
- Run the domain through URLScan.io and save the scan URL as evidence
- Note the exact domain name, registration date, and registrar
You'll need this evidence for every abuse report you file. The more specific and documented your report, the faster registrars act.
Step 2 — Check If It's Active
Look up the domain on URLScan.io — this tells you whether the domain is resolving, what it's showing, and what infrastructure it's using. Also check MX records using MXToolbox — if MX records are configured, the fake domain is already set up to send and receive email, which makes it a higher priority threat.
Step 3 — Contact the Registrar
The registrar — the company that sold the domain — is your most powerful lever. They can suspend the domain entirely, making it immediately inactive. Find their abuse contact through the WHOIS record and send a clear, specific report:
- Your company name and legitimate domain
- The fake domain and why it impersonates your brand
- The registration date and WHOIS evidence
- Any active abuse you've already seen (emails, fake website)
- A clear request for immediate suspension
Be specific, not generic. Registrar abuse teams receive hundreds of reports daily. A report that clearly explains who you are, what the fake domain is, why it's impersonating you, and what you want them to do gets prioritised over a vague complaint.
Step 4 — Contact the Hosting Provider
If the fake domain is actively hosting a website, file a separate abuse report with the hosting provider. Even if the registrar is slow to act, the hosting provider can pull the site's content, which neutralises the most visible threat while you wait for the domain suspension.
Step 5 — File with Disruption Services
Regardless of whether the domain is actively hosting anything, submit it to blocklist and disruption services. This limits what the fraudster can do with it even before it's formally taken down:
- Google Safe Browsing — flags the domain across Chrome, Firefox, and Safari
- Spamhaus DBL — blocks email from the fake domain on most mail servers globally
- PhishTank — adds it to the community phishing database
- Microsoft SmartScreen — flags it in Edge and Windows Defender
Step 6 — Escalate to ICANN if Needed
If the registrar hasn't responded within 5 business days, file a formal complaint with ICANN at icann.org/compliance/complaint. ICANN oversees all accredited registrars and can compel them to address abuse reports. Registrars take ICANN complaints seriously because non-compliance can affect their accreditation.
How to Prevent This Happening Again
Once you've dealt with the immediate threat, take these steps to protect yourself going forward:
- Register common variations of your domain — your name with hyphens, common typos, alternative TLDs
- Set up Google Alerts for your brand name combined with words like "scam", "fake", "phishing"
- Configure DMARC on your domain so fraudsters can't send emails appearing to come from your real address
- Tell your clients and suppliers to call you directly before actioning any unusual requests received by email
Don't Have Time to Handle This?
The process above works — but it takes time, persistence, and knowledge of which contacts to hit and how. If you need this handled fast while you focus on running your business, BOO! does exactly this.
We manually investigate the fake domain, craft targeted abuse reports for each specific operator, and follow up through every channel until it's down. $200 flat, only charged when the domain is successfully removed. Zero charge if we can't get it done.