What is domain hijacking?
Domain hijacking involves altering the registration of a domain name without consent from its rightful owner or through misuse of privileges granted...
A lookalike domain is a web domain designed to closely resemble a legitimate or trusted domain, often to deceive users into thinking it is the genuine site. Cybercriminals typically use these domains for phishing attacks, credential theft, or other fraudulent activities.
Lookalike domains exploit user trust by mimicking the appearance of a legitimate URL. They may incorporate the following:
Read also: What is domain name spoofing?
In November 2025, cybersecurity researchers identified a phishing campaign that demonstrated how convincing lookalike domains are being used to deceive users at scale. In this case, attackers registered and deployed the domain “rnicrosoft.com”, designed to closely resemble the legitimate microsoft.com, in an attempt to impersonate Microsoft and trick victims into engaging with malicious content.
The deception relies on a visual trick known as character substitution, where the combination of the letters “r” and “n” can resemble the letter “m” in many fonts. This subtle manipulation makes the fraudulent domain difficult to distinguish from the real one, particularly in fast-moving email environments or on mobile devices where URLs are often only glanced at rather than fully inspected. Cybercriminals typically use these domains in phishing emails that mimic trusted communications, such as security alerts or password reset notifications. Unsuspecting users are then directed to fake login pages where credentials are harvested and later used for account takeover or broader network compromise.
The “rnicrosoft.com” example is an indication of the growing sophistication of phishing tactics, where attackers increasingly rely on visual deception and brand impersonation rather than obvious spelling errors. It also reinforces the importance of careful URL inspection and domain awareness as essential defences against modern email-based threats.
Go deeper: Attackers are now using ‘rnicrosoft.com’ to trick victims
Cybercriminals frequently exploit lookalike domains for a range of malicious purposes. Here are some of the most common ways they are used to deceive and harm users:
Related: What are the most common cyberattacks in healthcare?
Preventing and detecting lookalike domains requires a combination of caution, technology, and proactive measures. By staying vigilant and implementing the following strategies, individuals and organizations can mitigate the risks associated with these domains:
See also: HIPAA Compliant Email: The Definitive Guide
Risks include phishing attacks, identity theft, malware infections, financial fraud, and brand reputation damage.
Lookalike domains exploit human error, such as quickly scanning URLs or trusting familiar-looking names. They often accompany convincing phishing emails or ads, increasing their credibility.
Industries like finance, healthcare, e-commerce, and technology are common targets because they handle sensitive data and financial transactions.
Domain hijacking involves altering the registration of a domain name without consent from its rightful owner or through misuse of privileges granted...
Domain name spoofing is when hackers attempt to trick users by pretending to be a website or email domain. Domain spoofing aims to fool a user into...
Attackers are using trusted cloud infrastructure to hide phishing activity behind legitimate domains.
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.