Brand and Domain Impersonation: Protecting Your Name Beyond the Inbox
Most email security protects your people from what lands in their inboxes. This is the opposite problem. Someone registers a domain that reads almost like yours, clones your website, and uses your name to defraud your customers, out where you cannot see it. Your filter never touches it and your DMARC record never sees it. Here is how brand and domain impersonation works, and what actually stops it.
Ask most organisations how they defend their brand online and they will point at their email security and their firewall. Both matter, and both look inward. They protect the people and systems inside your perimeter. But a whole class of attack never comes near your perimeter at all. It happens on domains you do not own, on servers you do not run, aimed at people who are not your employees. The attacker is not trying to get into your organisation. They are borrowing your name to rob the customers and partners who trust it, and the first you usually hear of it is when one of them has already been caught.
Brand and domain impersonation is the abuse of your name against people outside your organisation. Attackers register lookalike domains, clone your website and spoof your brand to defraud your customers and partners. Your email filtering protects your inboxes, not theirs, and DMARC only protects your exact domain, not the near misses. Defending your brand means watching the wider internet for abuse of your name and getting fraudulent sites taken down, which is a different job from securing your own mail.
The attack you cannot see from your own inbox
The reason this threat is so easy to underestimate is that it is invisible from where you sit. Nothing arrives in your inboxes. Nothing trips your controls. A criminal registers a domain that looks like yours, stands up a copy of your login page or your invoice template, and sends it to your customers or your suppliers. To them it looks like you, because it is wearing your brand, and they have no reason to doubt a message that matches everything they already know about you. The fraud plays out entirely on the outside, and the damage lands on people you cannot warn because you do not even know it is happening.
How brand and domain impersonation works
The methods are well worn and cheap, which is exactly why they are common.
- Lookalike and typosquatting domains. The attacker registers a domain that reads almost like yours, swapping one letter, adding a word, or using a different ending. At a glance it passes for the real thing, and it is theirs to do as they like with.
- Cloned websites. Your public site, your customer login or your payment page is copied pixel for pixel and hosted on the lookalike domain, ready to harvest credentials or card details from anyone who believes they are dealing with you.
- Brand spoofing across email and the web. Your logo, your tone, your templates and your people's names are reused in messages and pages designed to move your customers to act, from fake invoices to fake account warnings.
None of this requires breaking into anything of yours. The whole point is that it sits outside your walls, using nothing more than the public trust your brand has earned.
Why DMARC and email filtering do not cover this
This is the part that surprises people, because they assume the email controls they already have close the gap. They do not, and it is worth being precise about why.
- DMARC protects your exact domain, not the near misses. Enforced DMARC stops an attacker spoofing your real domain, which is essential. But a lookalike is a different domain, one the attacker owns, so it passes its own authentication cleanly and your DMARC record never sees it. DMARC shuts your own front door. It says nothing about the house next door built to look like yours.
- Your filtering protects your inboxes, not your customers'. A secure email gateway inspects mail coming to your people. When the fraudulent message goes to your customers instead, it never passes through anything you control, so nothing you have deployed can catch it.
So the two controls most organisations lean on are both looking the wrong way for this threat. They guard the inside. Brand impersonation attacks the outside.
The damage
The harm from brand abuse is real even though it happens elsewhere. Your customers lose money to fraud they attribute to you. Cloned login pages harvest credentials that unlock real accounts. Fake invoices divert payments that were meant for you or for your suppliers. And underneath the direct losses sits the slower damage to trust, because a customer who has been burned by something that looked exactly like you does not carefully separate the real you from the fake. The hardest part is the blindness. Because it all happens outside your perimeter, you frequently learn about it only after a customer has already been defrauded and comes to you angry, by which point the harm is done.
What brand protection actually does
Because the threat lives on the open internet, the defence has to look outward too. Effective brand protection does the watching you cannot do by hand.
- Continuous monitoring for lookalike domains. Newly registered domains that resemble your brand are spotted as they appear, often before they are ever weaponised, so you are not waiting for a victim to raise the alarm.
- Large scale automated scanning. The web is scanned at a scale no team could match by hand, hunting for typosquats, clones and misuse of your name across enormous numbers of sites.
- A tracker that fires when your pages are copied. A quiet marker embedded in your own site can activate the moment your HTML or your logos are lifted onto an unauthorised site, turning a clone into an alert rather than a surprise.
- Takedown of fraudulent sites. When a malicious lookalike is found, the point is to get it removed quickly, and to block it in the meantime so it cannot reach anyone through channels you do control.
Where Mimecast Brand Exploit Protect fits
We are a strategic Mimecast partner, and where brand abuse is a genuine exposure we recommend Mimecast Brand Exploit Protect for concrete reasons rather than as a default. It uses machine learning and scanning at very large scale to watch continuously for newly registered domains that resemble your brand, catching typosquatting and lookalike domains as they emerge. A dormant tracker embedded in your site activates the moment your HTML or logos are copied to an unauthorised site, so a clone reveals itself. It averages roughly a four hour resolution time on fraudulent domain takedowns, and while a threat is being removed it is immediately blocked across Mimecast email and web security, so it cannot reach your people through those channels in the meantime. It also shares that intelligence back into Mimecast email security, so what it learns on the outside strengthens the layer facing your inboxes. Where your name is worth impersonating, those are the reasons it earns its place, and where brand abuse is not a real risk for you, we will say so.
Not sure whether your brand is already being impersonated, or how exposed your customers are? Our free, interactive Email Security Assessment looks at authentication and impersonation alongside the other dimensions of email and collaboration defence, and returns an instant, personalised view of where the gaps are. It is a quick, honest place to begin.
Worried your brand is being used against your customers?
C4C helps organisations find out whether lookalike domains and cloned sites are trading on their name, and put monitoring and takedown in place before the damage lands. Vendor neutral, with no quota to fill.
Prefer email? Reach us directly at hello@c4cgroup.co.uk.
Frequently asked questions
What is brand impersonation?
Brand impersonation is the abuse of your organisation's name, logo and identity to deceive people who trust you, usually your customers and partners. Attackers register lookalike domains, clone your website and reuse your branding to send fraudulent messages or run fake sites. It happens outside your own perimeter, on domains and servers you do not control, which is what makes it so hard to see from the inside.
What is a lookalike or typosquatting domain?
It is a domain registered to resemble yours closely enough to fool a quick glance, by swapping a letter, adding a word or using a different ending. Because the attacker owns it, they can host a cloned site or send mail from it as they wish. Typosquatting specifically relies on small misspellings people do not notice, and it is one of the most common foundations for brand impersonation fraud.
Does DMARC stop brand impersonation?
No, not on its own. Enforced DMARC stops an attacker spoofing your exact domain, which is important, but a lookalike domain is a different domain that the attacker owns, so it passes its own authentication and your DMARC record never sees it. DMARC shuts your own front door. Brand impersonation uses the house next door built to look like yours, which needs monitoring and takedown, not authentication.
How do you take down a fraudulent lookalike domain?
A takedown is a request to the registrar or hosting provider to remove the malicious site, backed by evidence that it is impersonating you. Doing it quickly matters, so brand protection services specialise in finding fraudulent domains and driving fast takedowns, often within hours, and blocking the threat across your own email and web channels in the meantime so it cannot reach your people while it is being removed.
How is brand protection different from email security?
Email security looks inward, protecting your people from what arrives in their inboxes. Brand protection looks outward, watching the wider internet for abuse of your name aimed at people outside your organisation. Your filtering never touches a message sent to your customers from a lookalike domain, because it never passes through anything you control. The two are complementary, and each covers a gap the other cannot.
Who is targeted by brand impersonation?
The victims are the people who trust your brand, chiefly your customers, your partners and sometimes your own staff, while your organisation carries the fraud losses and the reputational harm. Any organisation with a recognisable name, an online login or a payment relationship is worth impersonating, and consumer facing brands, financial services and anyone handling payments tend to see it most. The bigger the trust in your name, the more it is worth abusing.