DefendDomain

Prevention guide

How to prevent brand impersonation: close what you can, spot the rest early

Some brand impersonation you can close off yourself. Nobody can stop the rest being set up, so the aim is to see it early and have it taken down fast. Here is the order to do it in.

David Batey•05/10/2026

You can stop most forged email sent in your company's exact domain from reaching anyone's inbox. The DNS record that does it is called DMARC, and plenty of companies that have one are still running it in a mode that only watches. What you cannot stop is someone registering a domain that looks like yours. Any name has hundreds of plausible lookalikes across hundreds of domain endings, and nobody can buy them all.

So preventing brand impersonation is two jobs, done in order. First, close everything that is yours to close: your own domains, the names a customer is most likely to mistake for yours, and the rule your finance team, customers and suppliers follow when someone asks for money. Most of that is done once. Second, keep the lookalikes you could not close short-lived: see them when they are registered, and have them taken down the day they are used on your customers, staff or suppliers. That job never finishes, and it is where the cost is decided.

TL;DR

Close what is yours to close (mostly a one-off):

  1. Set your domain to reject email you did not send, and lock down the domains you own but do not use.
  2. Remove old subdomains that point at services you no longer use.
  3. Register the few lookalikes a customer would most likely mistake for you, and claim your name on the main social platforms.
  4. Agree how payment changes are confirmed, and tell your finance team, customers and suppliers in writing.
  5. Give customers and staff one place to report anything that looks like you.

Spot the rest early (never finished):

  1. Watch for lookalikes of your domain and company name from the day they are registered, including ones that only send email.
  2. Decide now who gets a lookalike taken down, and how quickly.

Steps 6 and 7 never stop, and they are what DefendDomain runs for you. To start, run a free check of the lookalikes already registered against your domain.

If someone is impersonating you right now, go straight to our guide for a lookalike emailing your customers or a copied website, or ask us for urgent help. This guide is for the work before it happens. If you are still deciding whether it deserves the effort, read how serious brand impersonation is first.

Close what is yours to close

None of these five steps needs a budget beyond someone's time and a few domain registrations.

Step 1: Make your domain reject email you did not send

Unless your domain tells receiving mail servers otherwise, anyone can send email in its exact name. The record that tells them is DMARC, which works alongside SPF and DKIM, the records that list and sign the services allowed to send for you.

Many companies publish a DMARC record and stop at its monitoring setting, written p=none. In that mode, forged email in your domain's name is still delivered, and you only hear about it if you collect the reports. Moving the policy on to quarantine and then reject is what stops it: receiving servers then send unauthorised email to spam, or turn it away.

The move stalls for a predictable reason. Every service that legitimately sends as you, such as your invoicing system, CRM, marketing platform and helpdesk, has to be authenticated first, or its email starts failing too. Ask whoever runs your email for that list and a date.

Then cover the domains you own but never send email from: an old brand, the domain from before a rebrand, the registrations from step 3. Publish records on each saying it sends no email, with a DMARC policy of reject. Receiving servers that check will then turn away anything sent in its name.

Step 2: Clear out the subdomains you have forgotten

Most companies have more subdomains than anyone remembers: a help centre, an events page, an old campaign site, each pointed at an outside service when it was set up. When the service is cancelled but the record pointing at it stays, someone else can sometimes claim that service and publish their own page at your address, under your real domain name.

Nobody needs a lookalike domain if they can borrow a forgotten corner of your real one. A login page on your own domain passes the checks a careful customer or employee has been taught to make.

Ask for a list of every subdomain in your DNS, check each still points at something you use, and delete the rest. Then make removing the record part of cancelling any service.

Step 3: Register the obvious names, and claim your name on social platforms

Buy the handful of lookalikes a customer is most likely to type or trust by mistake: your name on the main endings for the countries you sell into, your most common misspelling, and the hyphenated version if your name has two words. Point them at your website and lock them down for email as in step 1.

Then stop. Buying every variation costs a great deal and still leaves gaps, because versions that tack a word onto your name, like yourname-accounts.com, never run out. That is what step 6 is for. More on the limits of defensive registration.

Do the same on social media: claim your company name on the main platforms, including ones you do not use. Only the platform can remove a fake profile, so find out now where each takes impersonation reports. A registered trade mark makes those complaints, and any dispute over a domain, easier to bring.

Step 4: Agree how payment changes are confirmed, and put it in writing

Much of the costliest impersonation ends in a request for money: an invoice sent to a customer in your name asking for payment to a new account, or an urgent payment request sent to your finance team by someone posing as a director.

Decide the rule while nothing is happening. A sensible one: bank details change only after a phone call to a number already on file, and no urgent payment goes out on the strength of an email alone, whoever it seems to come from.

Then tell everyone who will need it, before they need it. Put it on every invoice, in the pack new suppliers receive and in the welcome email to new customers, so the rule is already in front of their accounts team on the day a fake invoice arrives. It applies inside the company too: a payment request in a director's name from an outside address gets the same phone call.

Step 5: Give customers and staff one place to report it

Your customers, suppliers and staff will sometimes see an impersonation before you do, because it was sent to them. Most will not know who to tell, and some will assume you already know.

Give them one route: a short page on your website listing the only domains you send email from, saying how you will and will not ask for payment, and giving one address to forward anything suspicious to. Tell staff the same address applies to them, and make sure someone reads it every working day. A report that sits unread for a week is a week the lookalike keeps working.

Spot the rest early

Steps 1 to 5 shrink what an impersonator can use. They do nothing about the domain someone registers tomorrow to look like yours, because nobody can stop that registration. For that part, the aim is to keep the lookalike's working life as short as possible.

Step 6: Watch for lookalikes from the day they are registered

A lookalike has to be registered before it can send a single email or show a single page, and the registration is public. So is a security certificate issued for it, which is what gives a copied site its padlock. Those are the earliest points at which an impersonation can be seen, sometimes well before anyone is targeted.

Watch for more shapes than misspellings. Lookalikes add a word to your name, move it to a different ending, or swap its words round. The Solicitors Regulation Authority warned on 2 October 2026 that someone posing as a finance manager at a law firm was emailing people with fm-legal[.]com in their signature. The firm's genuine domain is legal-fm.com. Public registration records show the lookalike was registered on 22 June, more than three months before the warning.

Watch your company's legal and trading names as well as your domain. Watch for email set-up as closely as for websites, because some lookalikes never host a page: they exist to send invoices and payment requests, and the warning sign is the domain being made ready to send email. And look out for copies of your website, which can sit on addresses with no resemblance to your name.

By hand, this is a job for every working day: a growing list of names to re-check, new certificates to look through, and a decision on every hit. It is often the first thing to slip in a busy week, and we have seen a lookalike go from registered to sending fraudulent email in under half an hour.

Step 7: Decide now who gets a lookalike taken down, and how quickly

A lookalike can usually only be taken down once it is used. The companies behind a domain need proof of impersonation before they act: a copied site, a fake login page, fraudulent email. One sitting empty usually gives them none. Watching early means you are ready when that changes: the domain is already known, its details are already gathered, and the takedown can start the day it is used.

Then someone has to do it. By hand, one lookalike means separate reports to every company whose infrastructure it uses, each in that company's own format. Some reports come straight back pointing you somewhere else. Some go quiet. All of them need chasing, and someone has to go back, day after day, to see whether the domain has really gone. A technology company in one of our case studies was getting fake recruitment sites taken down itself: each time one came down another appeared, and the same fight came round every week.

So decide who owns this step. If it is someone on your team, it will be done around their actual job.

Or hand steps 6 and 7 to us. DefendDomain keeps watch around the clock for lookalikes of your domain and company name, including ones set up only to send email, and for copies of your website, even on addresses unrelated to your name. You hear about a lookalike early, with the evidence already gathered. We run the takedown from the first report through every follow-up and check, and keep you updated on where it stands. There is no cap on takedowns on any plan, and we check the set-up of your own domains every day, so you know when steps 1 and 2 slip. Run the free domain threat analysis, or book a demo and we will show you what we find for your domain. More on how our brand impersonation protection works.

How serious is brand impersonation?

It depends on how long it runs and who it reaches. A lookalike writing to your customers can send their payments to an attacker's account. One that copies your login page can collect your staff's passwords. One writing to your suppliers in your name can order goods or redirect payments. When it comes to light, the cost lands on your desk: money to chase, accounts to reset, and customers who are no longer sure an email from you is really from you.

It is also rarely one domain. In the campaigns we have dealt with, about three in four involved a group of similar domains rather than a single one, so taking one down is seldom the end. If you are comparing tools for the watching, our buyer's guide to lookalike domain monitoring sets out the questions to ask.

Where the cost is decided

For the parts of your brand you control, prevention is a job you can finish: enforce DMARC, clear out the old subdomains, buy the obvious names, write the payment rule down. For the part you do not control, prevention is measured in time: how long a lookalike works before anyone notices it, and how long it takes to come down once it is used. Early detection and early takedown shorten both.

Start with where you stand today. Our free domain threat analysis checks more than 150 likely lookalikes of your domain, shows which are already registered, and flags any set up to send email.

Frequently asked questions

How do you prevent brand impersonation online?

Close what you control first: set DMARC on your domain to reject email you did not send, protect the domains you own but do not use, remove subdomains that point at cancelled services, register the few lookalikes customers are most likely to mistake for you, claim your name on social platforms, agree in writing how payment changes are confirmed, and give customers and staff one place to report impersonation. Then, for the lookalike domains nobody can stop being registered, watch for them from registration onwards and decide who gets a lookalike taken down the day it is used. DefendDomain runs the watching and the takedown for you.

Can you stop someone registering a domain that looks like yours?

Not every one. Any name has hundreds of plausible lookalikes across hundreds of domain endings, so buy the few a customer is most likely to mistake for you and watch for the rest. The companies behind a domain will rarely act on a lookalike just because it has been registered. Once it is used against you, for example to host a copy of your website or send fraudulent email, it can be taken down, and if you saw it at registration, the takedown can start that day.

Does DMARC stop brand impersonation?

It stops one kind. With a policy of quarantine or reject, DMARC tells receiving mail servers to filter or turn away email in your exact domain’s name that you did not send. Lookalike domains sit outside it, so enforce DMARC on your own domains and watch for lookalikes separately.

How serious is brand impersonation?

Serious enough to cost money from more than one direction. Customers can pay invoices into an attacker’s account, staff can hand over passwords on a copy of your login page, and suppliers can act on instructions from someone posing as you. The cost depends on how long the impersonation runs before it is shut down, which is why early detection and early takedown matter.

Keep reading

Which lookalikes of your domain exist already?

Run a free domain threat analysis