DefendDomain

Incident guide

Someone is impersonating my company by email: what to do now

A lookalike domain is writing to your customers and suppliers as you. Here is the first day’s response, in order, and how to find the lookalikes that have not been used yet.

David Batey•28/09/2026

A customer forwards you an email and asks whether it's genuine. It's signed by someone on your sales team, it has your logo in the signature, and it says your bank details have changed. Nobody at your company sent it. Look at the sender's full address and there is your company name with a word added, on a domain you have never owned.

Someone has registered a lookalike of your domain to write to the people who trust your name: the customers who pay your invoices, the suppliers who take instructions from your finance team, and sometimes your own staff. The customer who forwarded it is probably not the only one who received it.

TL;DR

First, check the full sending address. If it is a lookalike of your domain, this is the order:

  1. Warn your finance team and everyone being written to, today.
  2. Keep the evidence, with the full email headers.
  3. Find out whether anyone has replied or paid.
  4. Get the domain and its mailboxes shut down.
  5. Chase every report until it stops sending.
  6. Assume it is not the only one, and look for the others.

Steps 4 and 5 take the longest. Tell us what you have found and we will run them for you.

You can do every step below yourself. Steps 1 to 3 are yours whatever happens, because they are about your people and your customers. Steps 4 and 5 mean writing to every company involved, following up until each one acts, and starting again when the next domain appears. DefendDomain can do that part for you.

First, check what you are dealing with

Ignore the display name, which anyone can set. Look at the full address the email came from, and at the reply-to address, which can be different. It will be one of three things, and each has a different fix.

  • A lookalike of your domain. Your name misspelt, on a different ending, or with a word added, such as yourcompany-invoices.com. Someone registered it to impersonate you, and this guide is for you.
  • Your exact domain. If the address is exactly yours but the email did not come from your systems, your domain is being spoofed. That is fixed at your end: ask whoever runs your email to enforce DMARC on your domain, so that receiving servers reject mail your systems did not send.
  • One of your real mailboxes. If the email really did come from one of your accounts, that account has been compromised. Treat it as a security incident: reset the password, check the mailbox for forwarding rules nobody set up, and call your IT provider, and your cyber insurer if you have one.

If the lookalike also shows a copy of your website, our guide to cloned websites covers that side. If the impersonation is a fake social media profile or business listing, report it through that platform's own reporting tools, since only the platform can remove it.

Step 1: Warn your finance team and everyone being written to, today

Do this first, before the evidence is tidy. A bank transfer can leave a customer's account the same day it is requested, and a warning that arrives tomorrow may be a day late.

Start inside. Tell finance, sales and customer service what the lookalike address is and what the emails say, so anyone who is asked gives the same answer. Anyone who pays suppliers or changes bank details should confirm every change by phone, on a number they already hold, until this is closed. The domain writing to your customers can write to your staff too, and an urgent payment request from “the chief executive” is the same attack pointed inwards.

Then warn the customers and suppliers who received it, and the accounts teams you invoice regularly, because they are next in line. Keep it short and factual, and, in a private warning, give the lookalike address so their team can block it.

The most useful sentence in that warning is a rule their accounts team can apply to any email, including the ones you never hear about: we will never change our bank details by email alone.

Step 2: Keep the evidence

Everything after this runs on it: the takedown requests, a police report, and any conversation between your customer and their bank. Collect:

  • The emails themselves, forwarded as attachments or saved as files, so the full headers travel with them. A screenshot or a pasted copy loses the headers, and the headers show where a message really came from.
  • The lookalike domain, and every address used on it, including any reply-to.
  • Who received each email, and when.
  • Anything attached, such as a fake invoice or a letter on your letterhead.
  • Any replies your customers sent, and what came back.

Ask customers to forward what they received rather than describe it. And do not reply to the lookalike or try to catch the sender out. It warns them, and they can move to a new domain before you have dealt with this one.

Step 3: Find out whether anyone has replied or paid

Do not take a quiet inbox as good news.

The first email often asks for nothing. In one case we have written up, the attackers told a company's trade customers that its receivables had moved to a new factoring arrangement and asked them to reply for “updated, verified” bank details. The first email carried no bank details, so filters had nothing to flag. The account number only arrived once a customer replied.

So ask every recipient two questions: has anyone replied, and has anyone paid? If money has gone, the customer who sent it should call their bank straight away. The sooner the bank knows, the better the chance of stopping or recovering the payment. They should also report it: in the UK to Report Fraud in England, Wales and Northern Ireland, or to Police Scotland on 101, and in the US to the FBI's Internet Crime Complaint Center.

When a customer pays the wrong account, the loss starts with them and comes back to you: an invoice they believe is settled, an argument about who carries the loss, and a customer who reads every email from you twice from now on. By the time you find out, the cost is already yours.

Step 4: Get the domain and its mailboxes shut down

A lookalike that only sends email comes down when the companies behind it act, and for one domain that can be several:

  • The registrar it was bought through, which can suspend the domain and every address on it.
  • The email providers it sends through, and there can be more than one. In the case above, the domain sent through several email platforms at once, behind shell company names, so that losing one would not stop the rest.
  • The DNS provider that hosts the domain's records, which can also switch off the records its email depends on.
  • The blocklists that email security products draw on. A listing protects people who have never dealt with your company, and it works while the removal requests sit unanswered. In the case above, the domain was on major anti-phishing blocklists the same day, which hurt its delivery on every platform it used.

Report the emails as well. In the UK, forward them to the National Cyber Security Centre at report@phishing.gov.uk. In the US, report them to the FBI's Internet Crime Complaint Center. Ask the customers who received them to do the same.

How fast any of them acts depends on the report, and a domain with no website is a harder case to make than a cloned site. Anyone reviewing it can visit the address and find nothing there, so the report has to prove the impersonation from the emails: the headers, the lookalike next to your real domain, and what the messages asked for. Doing it yourself means writing that report again for each company, because each has a different abuse form, asks for different evidence and works through its own queue.

Step 5: Chase every report until it stops sending

The reports are the start. The wait for the domain to go offline is the long part. Reports come back marked “not our customer” or “contact the registrar”, tickets close without anything changing, and the same evidence goes out again to someone else. Someone has to phone help desks, answer every ticket, and push for an escalation when nothing moves.

Someone also has to keep checking whether the domain can still send. A closed ticket does not mean a dead mailbox. Even when you get its email accounts closed, the attackers are ready to move quickly to another email provider. The attack changes as you try to disrupt it. In the case above, a new sending platform was added partway through, and the disruption had to be extended to it as well.

That work tends to land on the finance director or the head of IT, often at month end: phone queues and ticket threads spread over days, while their own work waits.

If a lookalike is writing to your customers right now, this is the part to hand to us. Tell us what you have found, and we will send the reports, chase them and keep checking until the domain is offline.

Step 6: Assume it is not the only one

Registering a domain costs little and takes minutes. In about three out of four of the attack campaigns we have seen, the attackers registered a cluster of similar domains, not a single one. We have seen the next one registered in the same second as the first, ready for when the first is shut down.

So taking this one down is rarely the end. Be ready for the others: find out what else is registered around your name. Our free domain threat analysis shows which lookalikes of your domain are registered and which of them can send email. Check the results against the domains your own company owns, then look hard at any that can send email and that nobody recognises. Look for your name with words added, not only misspellings: the domain in the case above was a brand name with a product word attached, and typo checkers do not generate that shape.

Ideally, more than one of them comes down. A registrar will not normally act on a lookalike that has not been used yet, but it sometimes will when the evidence ties it to the one already used against you: the same registrant, the same registration time, the same email set-up. So report the lookalikes you find together, with that evidence, not one at a time. Whether the unused ones come down is the registrar's call, which is one more reason to keep everything from step 2.

Why your email security did not stop it

Most companies that end up here already have SPF, DKIM and DMARC set up on their domain, and many pay for an email security product too. It is fair to ask why none of it helped.

The emails never touched your systems. They went from the attacker's email provider straight to your customers' inboxes, so your own email security never saw them.

And DMARC answers a question the lookalike passes. It asks whether an email really came from the owner of the domain it claims to come from. That protects your exact domain, and it is worth having: if your policy is not yet set to reject, fix that this week. But the attacker owns the lookalike. They can set up the same authentication for it that you have for yours, and their email can pass the same checks.

What protects your customers from a lookalike is the domain being found and shut down, and that needs someone watching for it. Read more on what DMARC can and cannot do.

How to hear about the next one before your customers do

This time, you heard about the lookalike from a customer, after it had already written to them. The time between the day it was registered and the day that email reached you is where the cost came from, and it is the part you can change.

Sometimes that window is days. In a campaign Microsoft's security team described in September 2026, more than a million emails went out over three days in early August, impersonating the targets' own executives and a well-known software vendor, and asking accounts payable teams for payments of nearly $50,000. The lookalike of the vendor's domain had been registered three days before the first email. Sometimes the window is far shorter: we have watched registration to first fraud email take under thirty minutes. Either way, the watching has to be continuous.

How closely to watch comes down to what a lookalike would cost you.

If you run a small business, run our free domain threat analysis every week or two. The scan is a snapshot of what is registered today. It will not tell you when an empty lookalike is set up to send email next week, and it does not take anything down, but for some lookalikes, you will see the registration yourself rather than hear about it from a customer.

If a lookalike would cost you customers, payments or supplier relationships, the watching has to be continuous, and running the takedown should be somebody's job rather than a month-end side task. DefendDomain watches for lookalikes of your domain and your company name, including your name with words added, and notices when one is set up to send email, even if it never hosts a website. You hear about it early, often before it is used, with the evidence already gathered, so the takedown can start the moment it is. The takedown then runs end to end, including every follow-up and check, until the domain is offline, and the watching carries on for the next one. For finance teams, here is how that protects invoices and payments.

Why this cannot wait

Every day the lookalike keeps sending is another day of invoices paid to the wrong account, suppliers taking instructions from someone who is not you, and staff answering requests from a chief executive who never sent them. The redirected payments can be counted. The customers who start doubting every email from you cannot.

So start today. Warn finance and the people being written to, keep the evidence, and get the reports moving yourself, or tell us what you have found and we will take it from there. Then find out what else is registered around your name with a free domain threat analysis.

Frequently asked questions

What should I do if someone is impersonating my company by email?

Check the full sending address first. If it is a lookalike of your domain, warn your finance team and everyone who received the emails the same day, and tell customers you will never change your bank details by email alone. Keep the original emails with their headers, find out whether anyone has replied or paid, and get the domain and its mailboxes shut down by the registrar, the email providers it uses and the blocklists that email filters rely on. Then chase every report until it stops sending, and look for other lookalikes registered around your name. DefendDomain can run the takedown and the chasing for you.

Can a lookalike domain be taken down if it has no website?

Yes. The registrar can suspend the domain, the email providers it sends through can close its accounts, and the blocklists used by email security products can stop its mail being delivered. With no website to point to, the case has to be made from the emails themselves: the headers, the lookalike beside your real domain, and what the messages asked for. On your own, that means writing to each provider separately and following up for days until the domain is offline. DefendDomain can take that whole job on.

Why didn't DMARC stop emails from a domain that looks like ours?

DMARC protects your exact domain. It lets receiving servers reject email that claims to come from your domain but was not sent by you. A lookalike is a different domain, owned by the attacker, who can set up authentication for it so that its email passes the same checks. The emails also go straight to your customers’ inboxes without passing through your systems, so your own email security never sees them. Protecting people from a lookalike means finding the domain and getting it shut down.

Where do I report someone impersonating my company by email?

In the UK, forward the emails to the National Cyber Security Centre at report@phishing.gov.uk, and report any financial loss to Report Fraud in England, Wales and Northern Ireland, or to Police Scotland on 101. In the US, report it to the FBI's Internet Crime Complaint Center. A report puts the fraud on record. Shutting the domain down is up to the registrar and the email providers, so send your evidence to them directly too.

Will they come back with another lookalike domain?

Be ready for it. In our data, the attackers registered a cluster of similar domains, not a single one, in about three out of four campaigns, so the next domain is often already registered. We have seen one registered in the same second as the first. Report any you find together with the one already used: a registrar will sometimes act on an unused lookalike when the evidence ties it to the same campaign. And keep watching after the first takedown. A new lookalike of your domain that is set up to send email is often the first sign they are trying again.

Keep reading

Is a lookalike emailing your customers?

Tell us what you have found