Scam & Fraud Glossary

Domain spoofing

Making a web or email domain resemble a trusted one to slip past your judgement.

Domain spoofing is the art of making a web address or email domain look like one you trust. It overlaps with typosquatting but is broader: as well as look-alike misspellings, it covers pushing a real brand name into a subdomain (so login.yourbank.example-secure.co has nothing to do with your bank), swapping letters for similar-looking characters from other alphabets, and forging the 'from' address on emails.

The aim is to borrow a trusted name so a fraudulent page or message slips past your judgement. Because the deceptive part is often buried in the middle of a long address, a quick glance is exactly what it is designed to survive. The reliable check is to read the domain from the right: the true site is the name immediately before the top-level ending and the first single slash, and everything to the left of that can be invented freely. When in doubt, do not click through — navigate to the organisation yourself. Our walkthrough on checking whether a website is legit shows how to parse an address so a spoofed one gives itself away.