ReaperCloud

Lookalike Domains

Business email compromise doesn’t spoof your domain — it registers one that reads like it. We generate the plausible variants and check which already exist.

Try paypal.com, microsoft.com or turbosec.io

Why this matters

Authentication cannot catch it

A message from exarnple.com passes SPF, DKIM and DMARC perfectly — because it genuinely is from that domain. It is not a spoof. It is a different domain that reads like yours.

What we generate

Omissions, doubled letters, transpositions, adjacent-key slips, lookalike characters and sequences, hyphenation, bitsquats, other TLDs, added words, and Unicode homoglyphs that render as Latin letters.

The MX column is the one to read

A registered lookalike doing nothing is common — parking, defensive registrations, squatters. One with a mail server has been prepared to send, which is a different conversation.

A snapshot, not a guarantee

Registration takes minutes and costs almost nothing. An empty result today says nothing about next week, which is why this is worth re-running rather than filing.