Why Misspelled TLDs Help Phishers Look Legitimate
A domain ending in .cm can look almost identical to a familiar .com address when it appears in a rushed email, mobile notification or shortened link. The missing letter is easy to overlook, particularly when a recipient recognises the business name and expects an urgent request.
This technique is a form of typosquatting, where criminals register a domain that resembles a genuine one. They may copy a company’s branding, create a convincing sign-in page or send messages that imitate invoices, parcel alerts and account warnings. Similar tricks can involve .co, .om or misplaced letters within the second-level domain.
For Australian recipients, the risk is especially relevant across banking, online retail, healthcare and government services. Messages viewed on phones in Sydney, Melbourne or regional areas often receive only a quick glance, while local businesses commonly use both .com.au and .com addresses. A small difference in the domain ending can therefore have significant consequences.
The Visual Deception Behind A Misspelled TLD
A top-level domain, or TLD, is the final part of a web address, such as .com, .au or .org. A .cm address is associated with Cameroon, but in a phishing campaign it may be chosen because it resembles .com when the address is displayed in a narrow email preview or read quickly.
Attackers can also combine the altered TLD with a familiar subdomain, brand phrase or login path. An address such as secure-brand.cm/account may feel credible because the visible words match a known organisation. The browser will still treat it as a separate domain, even if its page copies the legitimate site perfectly.
Why Criminals Register These Domains
A misspelled domain can bypass a person’s visual expectations without requiring a technically complex attack. It may support a fake Microsoft 365 login page, a payment request, a parcel redirection form or a password reset notice. Once credentials are collected, criminals can use them for business email compromise, identity theft or further fraud.
These domains may also support email spoofing and malware delivery. A campaign can use the lookalike address as the sender, the destination of a button or both. Attackers often select names connected with Australian banks, retailers and government services because recipients are accustomed to receiving automated notifications from those organisations.
Why Email Authentication Still Matters
SPF, DKIM and DMARC help a receiving mail system assess whether a message was authorised by the domain it claims to use. They are valuable controls, but they do not automatically make every lookalike domain unsafe. If a criminal owns example.cm, that domain can potentially publish its own valid authentication records.
This is why domain reputation, sender identity and link inspection need to be considered together. A message can pass authentication for a newly registered domain while still impersonating a brand. Security teams can begin with a sender score check to examine trust signals and identify suspicious domain behaviour before relying on message content alone.
Warning Signs For Australian Recipients
An unexpected request to approve a payment, update a Medicare-related detail or confirm an Australia Post delivery deserves careful inspection. Scamwatch and the Australian Cyber Security Centre regularly warn about impersonation campaigns that use urgency, authority and familiar branding to pressure recipients into acting before they verify the sender.
The country-code ending matters too. A genuine Australian organisation may use .com.au or .au, although some businesses legitimately use .com and other domains. Customers should avoid assuming that any address containing an Australian-sounding brand is local. Checking the full domain, rather than just the display name, is safer.
Practical Checks For Domain Owners
Domain owners should monitor newly registered lookalikes, certificate records and changes in sender reputation. A comparison with similar organisations can reveal whether a domain has unusually weak authentication, poor delivery signals or a reputation gap. A benchmark checklist can help security and marketing teams review these differences consistently.
It is also sensible to protect high-risk brand variations where appropriate, publish a restrictive DMARC policy after legitimate senders are identified, and train staff to report suspicious messages. Australian organisations handling personal information should consider their obligations under the Privacy Act and maintain incident processes that support prompt investigation and notification where required.
Turning Detection Into Ongoing Protection
Large organisations rarely send from one system alone. Marketing platforms, customer support tools, cloud applications and transactional services may each use different domains or subdomains. A central verification process helps distinguish an authorised sender from a newly created lookalike and reduces the chance that an isolated warning is missed.
For teams connecting checks to a secure email gateway, the API trust controls can support automated decisions and reporting. This is useful for Australian retailers handling high-volume campaigns, professional firms protecting client correspondence and security teams monitoring domains across multiple brands.
A misspelled TLD succeeds because people process familiar names quickly. Combining careful domain inspection with authentication analysis, reputation monitoring and staff awareness makes that visual trick far less effective.