Clone phishing works because it doesn't need to invent anything
Most phishing advice assumes the attacker is building a fake message from scratch, which means it can be spotted by odd phrasing, unfamiliar branding, or an obviously wrong context. Clone phishing skips all of that. It starts from an email you already genuinely received — a real invoice from a service you use, a shipping confirmation, a password-reset notice — and copies it almost word for word. The one thing it changes is the part that matters: the sending domain, the link destination, or both, plus a dose of urgency that wasn't in the original.
Why this bypasses the instinct that usually works
Email phishing remains the most-reported scam type by volume, and one reason clone attacks succeed even against people who consider themselves careful is that pattern recognition — "this looks like the emails I always get from this company" — is exactly the signal being exploited. The email isn't unfamiliar; it's a copy of something familiar, which quiets the part of your attention that would normally flag something as off.
The specific things that actually change
- The sending domain. A lookalike domain — hyphenated, with an extra word, or a swapped character — is the most consistent tell.
cloudhostpro.combecomescloudhost-pro-support.com, close enough to pass a fast glance but structurally a completely different domain. - The link destination. The visible link text or button might read identically to the original, but the actual destination URL points somewhere unrelated to the real service.
- Manufactured urgency. The original invoice said "due March 14." The clone says "OVERDUE — account will be suspended within 24 hours." That injected urgency is deliberate: it's designed to get you to click before applying the same scrutiny you'd give an unfamiliar email.
Why side-by-side comparison beats reading either email alone
Read in isolation, a clone-phishing email can look completely convincing — that's the entire design. The domain difference is easy to miss reading top to bottom, but jumps out immediately when placed next to the original you know is genuine. The same is true for the injected urgency: it's obvious once you can see what the "normal" version of this email actually says.
What to do if you don't have the original on hand
If you don't have a previous genuine email to compare against, the same principle still applies in reverse: look up the company's actual domain independently (not by clicking anything in the suspicious email) and compare it character by character against the sender address. Most clone-phishing lookalike domains are designed to survive a fast read, not a careful side-by-side check.
The habit that stops clone phishing for good
Never act on a link inside an email that creates urgency around your account, payment, or credentials — instead, navigate to the service directly by typing its known URL or using a saved bookmark. This single habit defeats clone phishing regardless of how convincing the copy is, because it removes the attacker's only path to you: the link they control.
Frequently Asked Questions
Clone phishing copies a real, previously-sent email almost word for word — an invoice, a shipping notice, a password reset — rather than inventing a new fake message. It then swaps in a lookalike sending domain, a malicious link, or added urgency. Regular phishing is often spotted because it looks unfamiliar; clone phishing is dangerous specifically because it looks exactly like something you've already trusted.
A lookalike sending domain is the most consistent tell — something like cloudhost-pro-support.com standing in for the real cloudhostpro.com. It's designed to survive a fast glance but falls apart under a character-by-character comparison against the real domain.
Urgency is injected deliberately to short-circuit the scrutiny a familiar-looking email would otherwise not receive. If the original invoice said 'due in two weeks' and the suspicious copy says 'overdue, account suspended in 24 hours,' that difference in tone is itself strong evidence of a clone, independent of any technical signal.
Look up the company's actual domain independently — not by clicking anything in the suspicious email — and compare it letter by letter against the sender address. You can also call the company using a phone number from their real website (not one in the email) to confirm whether the message is genuine.
Yes — the Clone Phishing Email Comparator takes a genuine email you've received before and a suspicious one, then checks sender domain similarity, link destination consistency, and added urgency language, returning a single risk score with a breakdown of exactly what changed.