Domain spoofing is a technique used by cybercriminals to impersonate a trusted company, organisation or individual by using a falsified domain name or one that closely resembles the legitimate domain.
The aim is to make the fraud attempt convincing enough that the victim does not notice the difference.
For example, a cybercriminal may register a domain name that closely resembles that of one of a company’s regular suppliers. They can then send an email using the supplier’s logo, signature and communication style to request payment of an invoice into a new bank account.
A very small difference in the address may go unnoticed: replacing, adding or removing a single letter can be enough to create the appearance of a legitimate domain.
Why has hiring a cybersecurity consultant become essential for your business ?
Domain spoofing is particularly common in phishing campaigns and financial fraud. Attackers may try to obtain passwords, confidential information or money directly.
To reduce the risk, companies can secure their emails using mechanisms such as SPF, DKIM and DMARC, monitor domains that resemble their own and raise employee awareness of impersonation attempts.
It is also essential to put internal verification procedures in place. An unusual request to change bank details or make an urgent payment should, for example, be confirmed through another communication channel.
When it comes to domain spoofing, technology and human vigilance go hand in hand: an address that looks familiar does not guarantee that the sender is really who they claim to be.