Beyond Fake Reviews and Ad Fraud
Most merchants are aware of common threats like fake reviews and ad fraud. Fewer understand the risks lurking in the domain name system—and these threats often cause more damage because they operate invisibly.
Domain-based attacks exploit the trust customers place in your brand. When someone thinks they’re on your site, they behave accordingly: entering payment details, sharing personal information, and completing purchases.
Here are seven domain threats every Shopify merchant should understand.
1. Typosquatting
What it is: Registering misspelled versions of your domain name.
How it works: Attackers study common typing mistakes. For a store called bluebird.com, they might register:
blubird.com(dropped letter)bluebidr.com(transposed letters)bluebrid.com(adjacent key)bluebirdd.com(double letter)
When customers make these typos, they land on a fake site instead of yours.
Why it’s effective: People type quickly and don’t double-check URLs. Mobile keyboards make typos even more common. A customer who types your URL from memory is particularly vulnerable.
Real-world example: A fashion brand discovered three active typosquatted domains collecting orders with their exact storefront design. Customers received counterfeit products and blamed the real brand.
2. Combosquatting
What it is: Adding words to your brand name to create believable domains.
How it works: Attackers combine your brand with common suffixes or prefixes:
bluebird-official.combluebirdstore.comgetbluebird.comshopbluebird.combluebird-outlet.com
These domains don’t rely on typos—they look intentional and legitimate.
Why it’s effective: Customers assume brands have multiple domains for different purposes. An “official” store or “outlet” site seems reasonable. These domains often rank in search results for brand-related queries.
Real-world example: A skincare brand found [brand]-discount.com running “clearance sales” with 60% off. The site had been operating for months, intercepting deal-seeking customers.
3. Homograph Attacks
What it is: Using characters that look identical to letters in your domain.
How it works: Multiple characters look the same but have different underlying codes:
O(letter) vs0(zero)l(lowercase L) vs1(one) vsI(uppercase i)rnvsm(when next to each other)- Cyrillic
аvs Latina(visually identical)
A domain like bIuebird.com (with an uppercase I instead of lowercase L) looks exactly like bluebird.com in most fonts.
Why it’s effective: These attacks are nearly impossible to detect visually. Customers can’t see the difference, even if they check the URL bar carefully.
Real-world example: A premium watch retailer was targeted with a Cyrillic homograph domain. The fake site collected credit card details for weeks before detection.
4. TLD Squatting
What it is: Registering your exact brand name on different top-level domains.
How it works: If you own bluebird.com, attackers register:
bluebird.cobluebird.shopbluebird.storebluebird.netbluebird.io
These aren’t misspellings—they’re your exact brand on a different extension.
Why it’s effective: Customers often guess at domain extensions. Someone who remembers your brand but not your exact URL might try .co or .shop first. Country-code TLDs (.co.uk, .ca) are especially risky if you have international customers.
Real-world example: A US-based supplement brand found their exact brand name registered on twelve different TLDs, with five actively selling counterfeit products.
5. Subdomain Spoofing
What it is: Using your brand name as a subdomain of a different domain.
How it works: Attackers create domains where your brand appears before the dot:
bluebird.checkout-secure.combluebird.shop-deals.netbluebird.orders-status.com
At a quick glance, customers see “bluebird” and assume it’s legitimate.
Why it’s effective: People are trained to look for the brand name in URLs, but many don’t understand that what comes after the brand name matters most. The actual domain here is checkout-secure.com, not bluebird.
Real-world example: A phishing campaign used [brand].secure-checkout.net in fake shipping notification emails. Customers clicked, saw the brand name in the URL, and entered payment details.
6. Email Domain Spoofing
What it is: Sending emails that appear to come from your domain.
How it works: Without proper email authentication, attackers can forge the “From” address on emails. Customers receive messages that look like:
- Order confirmations from
orders@yourstore.com - Shipping updates from
shipping@yourstore.com - Password reset requests from
security@yourstore.com
The emails link to fake sites designed to collect credentials or payment information.
Why it’s effective: Email is trusted. When customers see your domain in the sender field, they assume it’s really from you. Combined with copied branding, these phishing emails are convincing.
Real-world example: A home goods brand had customers receive fake “order issues” emails asking them to re-enter payment details. The emails passed spam filters because the brand hadn’t configured DMARC.
7. Expired Domain Hijacking
What it is: Registering domains you previously owned but let expire.
How it works: When you don’t renew a domain, it eventually becomes available for anyone to register. Attackers monitor expiring domains for:
- Old business domains you no longer use
- Domains from past marketing campaigns
- Seasonal or promotional domains
- Typos you once owned defensively
Once they own the domain, they benefit from any existing backlinks, search rankings, and direct traffic.
Why it’s effective: These domains have history. They may still receive traffic from old links, bookmarks, or muscle memory. Customers who remember an old URL have no reason to suspect it’s changed hands.
Real-world example: A brand let a promotional domain from a holiday campaign expire. Six months later, it was hosting a fake store using cached versions of their original site design.
How to Check Your Exposure
Understanding these threats is the first step. The next step is finding out which ones apply to your brand.
Start with these actions:
- Search for your brand name + common typos on domain registration sites
- Check major TLDs for your exact brand name (.com, .co, .shop, .store, .net)
- Set up Google Alerts for your brand name + “scam” or “fake”
- Review your DNS records for SPF, DKIM, and DMARC configuration
- Audit domains you own and verify auto-renewal is enabled
Prevention Checklist
Proactive defense costs far less than reactive cleanup:
- Register obvious typos of your main domain
- Secure your brand on important TLDs
- Configure SPF, DKIM, and DMARC for email authentication
- Enable auto-renewal on all domains you own
- Monitor for new domain registrations weekly
- Document your takedown process before you need it
The Ongoing Battle
Domain threats aren’t a one-time problem. New domains get registered daily. Attackers adapt their tactics. The brands that stay protected are the ones that maintain continuous visibility.
Manual monitoring works for a while, but it doesn’t scale as your brand grows. The bigger you get, the more attractive you become as a target.
Want to see what domain threats exist against your brand right now? Install Recon on Shopify to scan for typosquatting, lookalike domains, TLD squatting, and email security gaps.
Recon detects this automatically. Install free on Shopify →
← All posts