When a fraudster wants to impersonate your supplier, they have two options. Spoof the real domain — increasingly hard now that DMARC is spreading. Or buy a domain that merely looks like it, which they fully control, and from which everything is technically, perfectly authentic. The second costs about fifteen dollars. In July 2026 I set out to find how many of those twins already exist for brands everyone here knows.
It is a domain name chosen to be mistaken for yours. One extra letter, an i swapped for a 1, a hyphen removed — or, most effective of all, your exact name with .ca instead of .com.
What makes it formidable is that it is legitimate. The fraudster is its declared owner. They can publish a flawless SPF record on it, sign their mail with DKIM, set DMARC to reject. Every technical check comes back green, because they are not lying: the message really does come from the domain it displays. The lie is not in the technology, it is in the resemblance.
That is exactly why good DMARC on your own domain does not protect you here. DMARC stops people writing from your domain. It can do nothing about someone writing from the domain next door.
For each of the 26 brands I generated the most common typographic variants — the same ones Cyberbilan's own lookalike detector produces: visual substitutions, omitted letter, doubled letter, two letters swapped, hyphen removed, and extension change. Then I queried public DNS for each: does the domain exist, and can it receive mail?
A registered domain is not necessarily hostile. Plenty of companies buy their own lookalikes precisely so that nobody else does. So they had to be separated out. I compared each lookalike's name servers with the official domain's: identical hosting means a defensive registration. Then, for the ones that remained, I cross-checked a second time against mail servers, which pulled one more domain out of the "third party" pile.
Of the 64 lookalikes held by a third party, 30 have a mail server configured. That distinction is the heart of this study.
A domain bought to be resold later needs nothing at all: you let it sleep. Adding a mail server takes a deliberate extra step, and serves exactly one purpose — sending or receiving messages. It is the difference between a weapon in a drawer and a loaded one on the table. I cannot say what these domains do with that capability. I can say they have it.
I expected to find mostly misspelled names. It is the opposite: of the 30 armed lookalikes, 21 carry the brand's exact name, simply under a different extension. Only nine are genuine typos.
It makes sense. A typo only fools someone typing too fast. A different extension fools the person who reads carefully — because there is nothing to catch. The name is right. No letter is off. And almost nobody knows by heart whether their supplier is a .com or a .ca.
That is the most useful lesson here: "check the sender's address carefully" is not enough. You have to check the end of the address, the part nobody looks at.
You might think this is a big-brand problem. For you the opposite is true, for two reasons.
First, these 26 brands have people watching their name. You probably do not. The 25 defensive registrations I found are the mark of companies that thought to buy their own twin. A twenty-person business almost never does — and its name is just as available.
Second, the scam that costs a small business the most is not the one imitating a bank. It is the one imitating your regular supplier, with a real invoice number and a believable amount, to make you change a bank account number. That message does not need a million recipients. It targets one, and it knows your name.
.com, take the .ca — and the reverse. Ten dollars a year removes the fraudster's most convincing tool. But buying is not enough: a domain you own, never use, and never configured stays spoofable by anyone. Publish v=spf1 -all and a DMARC reject on it — two DNS lines that say "this domain never sends email, refuse everything". Do not chase the typos: there are countless variations, and that is not where it happens.And when a message leaves you uneasy without your being able to say why: Pro customers can forward it to their private Cyberbilan address and get a verdict within a minute — age of the sender's domain, resemblance to a known brand, links that do not lead where they claim. Exactly what this study checks, applied to one specific email.
Important clarification: this study accuses no one. Registering a domain that resembles another is perfectly legal, and some of those 64 domains surely belong to companies with no connection to the brand at all, to domain resellers, or to former partners. I observed no email being sent and draw no conclusion about anyone's intentions. The only finding is this: the infrastructure required for impersonation already exists, and it is in place around more than one brand in two.
Enter your domain: in 15 seconds we test your SPF, DKIM, DMARC and website — free, no signup, public data only.
Run the free check →Method and limitations: 26 well-known Québec brands (finance, insurance, public sector, telecom, media, retail, delivery, industry), kept because their name is at least six letters long — variants of a short acronym like “cgi” or “rbc” land on real, unrelated companies and would distort the count. For each, at most 15 variants (visual substitution, omission, repetition, transposition, hyphen removal, extension change), 390 in total, queried against public DNS (cloudflare-dns.com) on July 27, 2026: name servers present = domain registered, MX present = email-capable. Defensive/third-party split by comparing name servers with the official domain, then cross-checked against mail servers (which reclassified one domain). Limitations: a defensive registration hosted on a different DNS provider AND a different mail provider would be wrongly counted as third-party — so 64 is an upper bound. Conversely, 15 variation patterns do not cover every possible resemblance (added words, exotic extensions, non-Latin characters): the real number of lookalikes is higher. No website was visited, no email sent or received, no private data accessed — public DNS records only.