I went looking for the twins of 26 Québec brands. 15 have one that can send email.

By Cyberbilan July 27, 2026 7 min read

When a fraudster wants to impersonate your supplier, they have two options. Spoof the real domain — increasingly hard now that DMARC is spreading. Or buy a domain that merely looks like it, which they fully control, and from which everything is technically, perfectly authentic. The second costs about fifteen dollars. In July 2026 I set out to find how many of those twins already exist for brands everyone here knows.

In short:
26Québec brands analyzed
390name variants tested
64lookalikes held by a third party
30equipped to send email
57.7%of brands have an armed twin
70%are a plain extension swap

What a lookalike domain actually is

It is a domain name chosen to be mistaken for yours. One extra letter, an i swapped for a 1, a hyphen removed — or, most effective of all, your exact name with .ca instead of .com.

What makes it formidable is that it is legitimate. The fraudster is its declared owner. They can publish a flawless SPF record on it, sign their mail with DKIM, set DMARC to reject. Every technical check comes back green, because they are not lying: the message really does come from the domain it displays. The lie is not in the technology, it is in the resemblance.

That is exactly why good DMARC on your own domain does not protect you here. DMARC stops people writing from your domain. It can do nothing about someone writing from the domain next door.

What I measured

For each of the 26 brands I generated the most common typographic variants — the same ones Cyberbilan's own lookalike detector produces: visual substitutions, omitted letter, doubled letter, two letters swapped, hyphen removed, and extension change. Then I queried public DNS for each: does the domain exist, and can it receive mail?

A registered domain is not necessarily hostile. Plenty of companies buy their own lookalikes precisely so that nobody else does. So they had to be separated out. I compared each lookalike's name servers with the official domain's: identical hosting means a defensive registration. Then, for the ones that remained, I cross-checked a second time against mail servers, which pulled one more domain out of the "third party" pile.

The 390 variants tested — 26 Québec brands, July 2026
Free (nobody owns them)77.2%
Bought by the brand (defensive)6.4%
Third-party owned, no email8.7%
Third-party owned, with email7.7%

The detail that changes everything: the MX record

Of the 64 lookalikes held by a third party, 30 have a mail server configured. That distinction is the heart of this study.

A domain bought to be resold later needs nothing at all: you let it sleep. Adding a mail server takes a deliberate extra step, and serves exactly one purpose — sending or receiving messages. It is the difference between a weapon in a drawer and a loaded one on the table. I cannot say what these domains do with that capability. I can say they have it.

The 26 brands, by what sits around their name
A third-party twin that can send email15 brands
A third-party twin, no email configured6 brands
No twin found outside their control5 brands

The typo is not the real danger

I expected to find mostly misspelled names. It is the opposite: of the 30 armed lookalikes, 21 carry the brand's exact name, simply under a different extension. Only nine are genuine typos.

It makes sense. A typo only fools someone typing too fast. A different extension fools the person who reads carefully — because there is nothing to catch. The name is right. No letter is off. And almost nobody knows by heart whether their supplier is a .com or a .ca.

That is the most useful lesson here: "check the sender's address carefully" is not enough. You have to check the end of the address, the part nobody looks at.

Why this concerns you even if you are not a big brand

You might think this is a big-brand problem. For you the opposite is true, for two reasons.

First, these 26 brands have people watching their name. You probably do not. The 25 defensive registrations I found are the mark of companies that thought to buy their own twin. A twenty-person business almost never does — and its name is just as available.

Second, the scam that costs a small business the most is not the one imitating a bank. It is the one imitating your regular supplier, with a real invoice number and a believable amount, to make you change a bank account number. That message does not need a million recipients. It targets one, and it knows your name.

Four things to do this week

  1. Look at who is lurking around your name. Our lookalike-domain checker does exactly what this study did, on your domain, free.
  2. Buy the obvious variant, then make it mute. If you are a .com, take the .ca — and the reverse. Ten dollars a year removes the fraudster's most convincing tool. But buying is not enough: a domain you own, never use, and never configured stays spoofable by anyone. Publish v=spf1 -all and a DMARC reject on it — two DNS lines that say "this domain never sends email, refuse everything". Do not chase the typos: there are countless variations, and that is not where it happens.
  3. Set your DMARC to "reject". It does not block lookalikes, but it closes the other door, the easy one. Check where you stand in seconds.
  4. Change the internal rule. Stop saying "check the sender". Say instead: "before any transfer or change of banking details, we pick up the phone and call the number we already had — never the one written in the email." That is the only rule that survives a perfectly configured lookalike domain.

And when a message leaves you uneasy without your being able to say why: Pro customers can forward it to their private Cyberbilan address and get a verdict within a minute — age of the sender's domain, resemblance to a known brand, links that do not lead where they claim. Exactly what this study checks, applied to one specific email.

Important clarification: this study accuses no one. Registering a domain that resembles another is perfectly legal, and some of those 64 domains surely belong to companies with no connection to the brand at all, to domain resellers, or to former partners. I observed no email being sent and draw no conclusion about anyone's intentions. The only finding is this: the infrastructure required for impersonation already exists, and it is in place around more than one brand in two.

Can your business be spoofed?

Enter your domain: in 15 seconds we test your SPF, DKIM, DMARC and website — free, no signup, public data only.

Run the free check →

Method and limitations: 26 well-known Québec brands (finance, insurance, public sector, telecom, media, retail, delivery, industry), kept because their name is at least six letters long — variants of a short acronym like “cgi” or “rbc” land on real, unrelated companies and would distort the count. For each, at most 15 variants (visual substitution, omission, repetition, transposition, hyphen removal, extension change), 390 in total, queried against public DNS (cloudflare-dns.com) on July 27, 2026: name servers present = domain registered, MX present = email-capable. Defensive/third-party split by comparing name servers with the official domain, then cross-checked against mail servers (which reclassified one domain). Limitations: a defensive registration hosted on a different DNS provider AND a different mail provider would be wrongly counted as third-party — so 64 is an upper bound. Conversely, 15 variation patterns do not cover every possible resemblance (added words, exotic extensions, non-Latin characters): the real number of lookalikes is higher. No website was visited, no email sent or received, no private data accessed — public DNS records only.