A password manager just got impersonated by a domain one letter off
LastPass warned customers about phishing sent from lookalike domains it never owned — a reminder that DMARC doesn't stop a domain that merely resembles yours.
By Norbelys Chirinos, Co-founder
Founder-reviewed ·How we research and correct articles
On July 13, 2026, LastPass told its customers something that should unsettle anyone who thinks DMARC alone keeps their brand safe from impersonation: a phishing campaign was actively targeting its users, and none of the domains involved were ones LastPass had ever registered, owned, or authenticated. The attacker used lastpassnewsletter.com and lastpasscompliance.com, sending mail from hello@lastpassnewsletter.com and directing recipients to a fraudulent page designed to harvest LastPass master passwords. LastPass’s own systems were never touched — the domains simply looked close enough to the real thing to work.
Why DMARC has nothing to say about this one
This is worth dwelling on because it’s a genuinely common misunderstanding: DMARC, SPF, and DKIM authenticate mail claiming to come from your exact domain. They tell a receiving mailbox “if this message says it’s from norbelys.com, here’s how to verify that’s true, and here’s what to do if it’s lying.” None of that machinery has anything to say about a domain that isn’t yours at all — norbelys-newsletter.com or norbelysmail.com can publish their own perfectly valid SPF, DKIM, and DMARC records, pass every authentication check a mailbox provider runs, and still be a pure impersonation, because the attacker is authenticating their domain, not spoofing yours.
That’s exactly the shape of the LastPass campaign: a lookalike domain, properly set up on the attacker’s end, sending mail that authenticates cleanly while impersonating a brand it has no relationship to. A recipient’s mail client shows no authentication warning, because there’s nothing to warn about from a pure protocol standpoint — the message really is from lastpassnewsletter.com, exactly as claimed. The deception is entirely in the domain name itself, not in anything DMARC was ever built to catch.
Why this matters for a cold-email program specifically
If you send cold email at any volume, you’re already asking recipients to trust a sending domain they may not fully recognize — which makes your program a natural template for exactly this kind of lookalike attack. An attacker who wants to run a scam under your brand’s cover doesn’t need to break into anything you own; they can register yourcompany-updates.com or yourcompanymail.com, set up clean authentication on it, and send messages that will pass every technical check while doing real damage to the trust your actual domain has built. The victims of that campaign associate the bad experience with your brand, not with the technicality that it wasn’t really your domain.
There’s a second-order risk that’s easy to miss: a lookalike-domain campaign impersonating you can also poison your own deliverability indirectly. If enough recipients report messages from a domain that merely resembles yours, and enough of that gets fed into brand-reputation or similarity-based filtering that some mailbox providers use, it can create friction for your legitimate domain even though, strictly speaking, none of your own infrastructure was involved.
What actually helps
Defending against a threat DMARC can't see
Register the obvious variants of your own domain
Common misspellings, hyphenated versions, and the most likely TLD swaps (.net, .co, .io if you're on .com) are cheap insurance against someone else registering them first for exactly this purpose.
Monitor for new registrations that resemble your brand
Domain-watch services and even periodic manual searches can catch a lookalike registration before it's weaponized into a campaign, giving you a window to act — takedown requests, registrar reports, or at minimum an early customer warning — before recipients start reporting it.
Make your legitimate sending domains predictable and few
If customers only ever hear from you at one or two consistent, well-known domains, an unfamiliar one claiming to be you is easier for them to spot on their own. Sprawling across many different sending domains for different campaigns makes every one of them look equally plausible as 'the real one' — including the fake.
Have a fast, public response ready
LastPass's own response is the template: identify the domains by name, publish it immediately and publicly, and be explicit that the sender was never affiliated. Silence or a slow response gives an impersonation campaign more runway to do damage before anyone can distinguish real from fake.
Frequently asked questions
If I have DMARC at p=reject, am I protected from this kind of attack?
Not from this specific pattern. DMARC protects your exact domain from being spoofed by someone else. It does nothing to stop a different, similar-looking domain from being registered and used to impersonate your brand — that requires separate monitoring of new domain registrations, not authentication policy.
How would I even know if someone registered a lookalike of my domain?
Not automatically — this is exactly why proactive monitoring matters. Periodic searches for common misspellings and TLD variants of your domain, or a dedicated domain-watch service, are the practical way to catch a registration before it's used against you rather than after.
Does this affect small companies, or only recognizable brands like LastPass?
Any domain with an audience that trusts it is a viable target — the attacker doesn't need global brand recognition, just a specific list of people who'll recognize your name and lower their guard. A smaller, tighter-knit customer base can make the impersonation even more convincing, since a lookalike domain plus a familiar name is often enough.
Where Norbelys fits
Protecting a domain’s reputation only from the inside — perfect SPF, DKIM, and DMARC on your own infrastructure — leaves exactly this gap open. Norbelys’s DMARC monitoring keeps your own domain’s authentication honest, watching your real aggregate reports so nothing you actually own drifts out of alignment, which is the half of this problem that’s genuinely solvable with the right tooling.
The other half — someone else registering a domain that merely looks like yours — is a reminder that deliverability and brand protection are the same job wearing two hats, not two separate problems. If your outreach still runs from a scatter of loosely related domains, consolidating onto a small, consistent, well-monitored set through Norbelys makes both your own authentication and your recipients’ ability to spot an impostor stronger at the same time. Start sending from infrastructure built to be watched continuously, not configured once and forgotten.