---
title: "Sender research & look-alike domains"
description: "Who is this, in fifty words, and is the domain a look-alike?"
url: "https://openemail.uk/docs/knowledge/safety/sender-research"
area: "Knowledge base"
category: "Safety & authenticity"
status: "live"
---

# Sender research & look-alike domains

Who is this, in fifty words, and is the domain a look-alike?

## Details

- Click the sender’s name in a message to run a web search on the person and the domain behind them.
- The verdict from ingest sits above the answer, because only one of the two is authoritative: our own checks read this message’s headers and its links, while the search is a model’s background on a name and has never seen the message.
- Near-miss domains are called out: paypaI.com with a capital i where the l should be, or paypal-secure.com padded out to read past. The test is two edits from the brand name, or the brand name with something bolted on to it.
- The brand comparison is against twenty names worth impersonating: paypal, microsoft, apple, dhl, chase and the rest. A look-alike of your accountant’s domain is not on that list and never could be, so it is caught a different way: any domain that mixes alphabets inside a single word is called out on its own, whoever it is imitating. Mixing scripts is the technique rather than the target, and a domain written wholly in Cyrillic or Greek is a normal domain and is left alone.
- Domains spelt out of another alphabet are decoded before they are compared. pаypal.com with a Cyrillic а travels as xn--pypal-4ve.com, which is seventeen edits from paypal and matches nothing, so the name is decoded back to what a person would see, imitation letters are folded to the Latin ones they copy, and the result is compared to the brand. It is weighted above an ordinary near-miss: a spelling that had to be assembled out of two alphabets has no innocent version.
- A look-alike that passes DMARC and DKIM for itself, which costs an attacker nothing since it is their own domain, has its identity signals discounted to 45% of their weight, and 40 becomes 18 against a warning threshold of 30. Something else in the message has to fire as well, and it has to be something the discount does not touch: a link that reads as one domain and goes to another clears the bar on its own, and so does an executable attachment. An unauthenticated hop cannot be that something, because it only fires on a domain that failed DMARC and DKIM, which is the opposite of the one being discounted, and a single urgent phrase is not enough either: one “your account has been suspended” scores ten against a threshold of thirty, so it takes two of them plus a link.
