Truviss

Domain Phishing: The Complete Guide (2026)

Domain Phishing: The Complete Guide cover
Home/Blog/Domain Phishing: The Complete Guide (2026)
Domain & Phishing

Domain Phishing: The Complete Guide (2026)

Domain Phishing: The Complete Guide cover
TL;DR
  • APWG recorded 3.8 million unique phishing attacks in 2025, up from 3.76 million in 2024, and most of these rely on a lookalike domain to appear legitimate.
  • The average phishing site stays live for only around 12 hours before takedown (BlackBerry, 2025), which is why continuous monitoring beats periodic manual checks.
  • FBI IC3 recorded $215.8 million in direct phishing losses in 2025, up sharply from $70 million the year before.
  • A documented detect, verify, enforce process against your own domain and brand assets closes phishing domains faster and gives you an evidence trail if a case escalates.

What domain phishing and typosquatting actually look like

Domain phishing almost always starts with typosquatting, a domain registered on a common misspelling or visual variant of a real brand’s web address. A swapped letter, a doubled character, a numeral standing in for a similar-looking letter. The domain is then built to mirror the real site closely enough to pass a quick glance, most often cloning a login or checkout page to harvest credentials or payment details under the brand’s name.

APWG recorded 3.8 million unique phishing attacks across 2025, up from 3.76 million in 2024 (APWG, Phishing Activity Trends Report, Q4 2025). A large share of these depend on exactly this pattern: a domain close enough to a trusted brand’s real address that a customer doesn’t look twice before entering sensitive information.

Why lookalike domains are so effective

A lookalike domain doesn’t need to fool a security team, it only needs to fool a customer moving quickly, usually someone who clicked a link in an email or a text message and is already expecting to land on the brand’s real site. Pairing the domain with a valid SSL certificate removes the one browser warning most people would actually notice, so the page looks legitimate at a glance even to someone paying reasonable attention.

Phishing sites also don’t stay up for long. The average phishing site is live for only around 12 hours before it’s taken down (BlackBerry, 2025), which sounds reassuring until you consider how much damage a convincing fake can do to the right audience in that window, and how quickly a new one can go up to replace it.

The real cost of a phishing domain using your brand

The most direct cost lands on customers, not the brand: stolen credentials, stolen payment details, and in many cases money sent to an account that was never the brand’s own. But the brand absorbs the fallout regardless. Customers who realise they’ve been phished under a brand’s name associate the experience with that brand, not with the criminal who registered the domain, and support teams end up fielding complaints about a page the brand never built.

Phishing losses reported to the FBI’s Internet Crime Complaint Center reached $215.8 million in 2025, up from $70 million the year before (FBI IC3, 2025 Internet Crime Report), and that figure only captures reported financial losses, not the harder-to-measure cost of customer trust.

Manual domain watching versus continuous monitoring

Most brands start out checking for lookalike domains the way they check for most things online: occasionally, and manually, usually after a customer reports a suspicious email or a phishing page turns up in a search. This catches the domains that are already active and already causing complaints.

What it misses is the domain that’s registered today and weaponised next week. New domains can be registered, built out to mimic a real site, and pushed into a phishing campaign within days, well inside the gap between manual checks. Continuous monitoring closes that gap by watching new domain registrations and DNS activity for patterns that match a brand’s name, rather than waiting for a phishing page to surface on its own.

Building a domain takedown process that holds up

A workable process against domain phishing generally follows the same three stages as any other brand protection channel:

Detect continuously. Monitor new domain registrations and lookalike variants of your own domain and brand name, not just an occasional manual search.

Verify against your real domain portfolio and known partners, so a legitimate regional site or an approved reseller’s domain isn’t mistaken for an infringement.

Enforce with a documented trail, filed with the registrar or host, logged with enough detail (when it was found, what made it identifiable as a phishing clone) to support further action if the case escalates.

See how Truviss’s Domain Scanner catches lookalike and typosquatted domains the moment they’re registered.

Explore Domain Scanner

Common mistakes brands make

The most common mistake is only reacting once a phishing domain is already active and customers are already complaining, rather than watching for the registration itself. By the time a phishing page is live and indexed, some damage is usually already done.

A second is assuming a domain has to be an exact match to be a threat. Attackers deliberately use near-misses, a swapped character, an added hyphen, a different top-level domain, specifically so the domain doesn’t show up in a simple exact-match search.

A third is treating a single takedown as the end of the problem. A determined phishing operation will often re-register a near-identical domain shortly after the first one is taken down, which is why ongoing monitoring matters more than any single enforcement action.

Getting started

Start by mapping the domain variations most likely to be used against your brand, common misspellings, added or swapped characters, alternate top-level domains, then put continuous monitoring in place against that list rather than relying on customers or search results to surface the next one. Once detection is running, pair it with the same evidence-backed takedown process used for online brand protection more broadly, so enforcement is consistent regardless of which channel a threat shows up on first.

Frequently asked questions

How can I tell if someone has registered a phishing domain using my brand?

Manually searching common misspellings of your domain will catch some cases, but continuous monitoring of new domain registrations against your brand name is what catches a domain before it’s actively being used in a campaign.

Is registering a domain to impersonate another brand illegal?

Registering a domain specifically to impersonate a brand, particularly for phishing, generally breaches trademark law and most registrars’ acceptable use policies, which is why a documented takedown request to the registrar is usually effective.

How fast can a phishing domain be taken down once it’s found?

Timelines vary by registrar and host, but a documented, evidence-backed request is generally actioned faster than a vague report. Given that the average phishing site is only live for around 12 hours anyway, speed of detection often matters more than speed of takedown.

Do phishing domains only target large, well-known brands?

No. Any brand with an online presence and customers who might click a link can be targeted, and smaller brands often have fewer resources dedicated to watching for it, which makes automated detection more valuable relative to team size.

What’s the difference between typosquatting and brand impersonation?

Typosquatting is a lookalike domain, usually used for phishing. Brand impersonation is a fake social media account or page. Both fall under online brand protection but are detected and enforced through different channels.

Can a legitimate regional site or reseller domain get mistakenly flagged?

It shouldn’t, provided detection is verified against your real domain portfolio and known authorised partners rather than flagged on a name match alone. This is why the verify step matters as much as detection itself.