Sentinel · Brand & Booking Protection

How Clone Sites Intercept Your Hotel's Most Profitable Bookings

The booking a guest makes straight with you is the most profitable one you take. This is how clone sites, affiliate skimming, and brand impersonation step in front of those bookings, and how to take them back.

Clone Sites
Someone is ranking above you for your own name.
SORVEIL · SIGHTLINES
In this guide
  1. Why your bookings are worth taking
  2. What is taking your bookings
  3. How to tell if it is happening
  4. The seven protections
  5. What to do right now
  6. Frequently asked questions
  7. Closing the leak

Some of what poses as your hotel online is outright fraud: fake pages built to capture a guest's card details. Some of it is subtler, a third party earning a commission on a booking that should have come to you directly, at full rate. Both step into the same place, between a guest who meant to book with you and your own reservation system.

It happens more often than most hotels would guess. A site that looks legit ranks above you on Google for your own name and routes direct-intent guests through an affiliate link. A lookalike page collects a card. With rate parity loosened, the guest heading straight to you is the most profitable booking you can take, which is exactly why someone wants to intercept it. This piece covers both kinds: what is taking your bookings, how to tell if it is happening to you, and how to close the leak.

Your Direct Bookings Are Worth Taking

Rate parity used to hold this problem down on its own. Parity was the requirement, written into booking-site contracts, that a hotel's direct rate could not be lower than the rate on those sites. If every channel showed the same price, intercepting a booking barely changed what the guest paid, so there was little to gain. But this reality has changed thanks to EU regulations.

That requirement has loosened across many markets. Now your direct rate can be lower, and it keeps the full margin with no commission attached. That is the good news, and it is the whole reason a guest heading straight for your site is now the most profitable booking you can take. It is also why someone wants to step in front of it: the economics that reward your direct channel are the same economics that reward intercepting it. Here is what that interception actually looks like.

What Is Stealing Your Bookings

Each of these is a route used to pose as your hotel brand and step between you and a guest.

What Is a Hotel Clone Website (Lookalike Site)?

A clone website copies a hotel's name, photos, and branding to rank in search or in ads, then routes the booking through an affiliate link or a fraudulent payment page instead of the hotel's own reservation system. Guests believe they booked directly with the hotel. The hotel never sees the reservation or keeps the margin.

These sites are often a near-copy of your homepage on a domain one character off your own, say the-luxury-resort.com in place of theluxuryresort.com. Where the fake page collects card details, that is fraud, plainly. Where it forwards the guest to a booking site through an affiliate link, it is commission skimming, a different matter covered next.

What Is OTA Affiliate Arbitrage (Commission Skimming)?

Affiliate arbitrage is when a third party ranks content or buys ads against a hotel's own brand name, then reroutes the click through an OTA (online travel agency) affiliate link. The operator earns a commission on a booking the hotel would otherwise have received directly, at full rate. This targets hotels because rate-parity rules that used to block it have loosened, so direct-intent guests are newly profitable to intercept.

The distinction that matters: the skimmer affiliate is a rogue operator inside a major OTA's affiliate program, not the OTA itself. In the best case the booking is real and the guest pays the normal rate. What you lose is the margin and the direct relationship: the guest's email, the chance to upsell, the profile for next time. That is why it reads as legitimate and why it is easy to miss.

It also explains why a fake page can outrank you on your own name. These operators put real SEO and now AEO work into ranking. They build pages aimed at your exact name, keep them fresh, and sometimes buy ads on it. If you never set your own site up to compete for brand search, a page built only to rank on your name can sit above you.

How Does Social Media Impersonation Work?

In plain words, it looks real. A fake account copies your name, your logo, and your photography on Instagram or Facebook, then messages guests to confirm a booking or collect a deposit. Early on it has few followers, so it looks small and harmless, which is exactly when it is easiest to remove. A guest who sends a deposit to that account experienced it as your hotel.

What Is Booking-Path Interception?

Booking-path interception is anything that steps into the path between a guest who wants to book with you directly on your own reservation system. It has an on-property form too. The bad news is that even on a fraudulent Wi-Fi network, or through a booking engine someone has tampered with, an attacker can reroute a guest's payment or reservation without either of you noticing.

Every route ends the same way. A guest who meant to book with you either pays someone else, hands a card to someone else, or books at a rate that pays a commission you never agreed to. The guest's intent was yours. The booking was not.

The threatGuest seesWhat it costs you
Clone / lookalike siteA page that looks like yours, ranked high in the search for your nameCard fraud in your name, or a booking you pay a commision for
OTA affiliate arbitrageYour name in the results, then a booking page that looks officialThe margin and the direct relationship on a full-rate booking
Social media impersonationA profile with your name and photos, replying to themLost deposits and a guest who blames you
Booking-path interceptionA normal-looking booking or payment stepRerouted payments and reservations you never receive

How to Tell If Your Hotel has a Clone Site?

The clearest signal is a website the hotel did not create, sitting above or beside the site you own when someone searches the hotel's name. A second signal is a guest's booking confirmation priced or routed differently than the hotel's own direct rate. A hotel can check this in under five minutes by searching its own name from a signed-out browser and reading every result on page one.

The Five-Minute Brand Search Check

  1. Open a private or incognito window, so your own history does not shape the results.
  2. Search your hotel's exact name on Google. Repeat on Bing and one other engine.
  3. Read every result on page one, ads included. Note anything that is not your own site, your verified profiles, or a known partner.
  4. Look closely at links that use your name. A domain that is a misspelling, or has a different ending than your own, is worth a second look.
  5. If a result looks like a copy of your site, do not enter any details. Note the address it sends you to, and whether the final booking page is yours or a booking site with an added code in the link.
  6. Save screenshots and the exact web addresses. This is the evidence you will need to report anything you find.

Warning Signs from Guest Complaints and Booking Data

  • A guest arrives with a confirmation you have no record of.
  • A guest says they paid a deposit you never received.
  • A guest mentions an email from you that your team did not send.
  • Guests report a rate, or a payment page, that is not yours.
  • Direct bookings fall with no clear reason, while guests search your name as often as ever.
  • Card chargebacks reference reservations you cannot find.

One of these can be a coincidence. Two or three together is a pattern worth checking.

Where to Check for Lookalike Domains

Start with the obvious variations of your own name: common misspellings, extra or missing hyphens, and different endings. A domain's ending is its TLD, or top-level domain, the part after the final dot (.com, .co, .hotel, .travel). Registering a lookalike under a different TLD is a common move.

Two patterns are worth knowing by name. Typosquatting is registering the misspellings a guest is likely to type. Homograph or IDN spoofing uses lookalike letters from other alphabets, so a domain can read as your name to the eye while being a different address underneath.

WHOIS is the public record of who registered a domain and when. A free WHOIS lookup usually shows a recent registration date and the company to contact if you need something removed. For continuous coverage, monitoring services flag new registrations that resemble your name, which is more than a busy team can do by hand.

SightlinesNotes for hoteliers on
protecting earned profit
SORVEIL · sorveil.com
SORVEIL
You're in.
You're about to get the tools to keep more of your profit.
Where profit leaks stop.
Get your notes on keeping more of your profit.
Occasional. No spam. Leave anytime.
turn it over

How Can Hotels Protect Themselves Against Clone Websites and Impersonation?

Protecting a hotel from clone websites and impersonation requires effort and expertise you may not have in house. But don't be discouraged. Sorveil runs this for hotels through Sentinel, so it is not one more thing your team has to own. Here are the 5 ways hotels can protect themselves:

  1. Register your trademark if the cost makes sense.
  2. Build a domain portfolio around your brand name.
  3. Set up email authentication (SPF, DKIM, and DMARC).
  4. Verify and connect your site in Google Search Console.
  5. File a trademark complaint with Google Ads.

The rest of this section takes each one in turn. The difficulty shown on each is a rough guide to the effort involved, out of ten.

Register Your Trademark

Difficulty 6 / 10

A registered trademark is the legal backbone of everything else here. It is what lets you file complaints with Google and ask a registrar or host to remove a site copying your name. You register the name and the logo with your national trademark office. In the United States that is the USPTO, the US Patent and Trademark Office. To cover several countries with one filing, the Madrid Protocol is an international system that routes a single application to the offices you choose. Expect roughly $350 in US government fees to start (as of 2026, per the current USPTO fee schedule), plus attorney fees if you use one, so a typical filing runs about $1,000 to $2,000. Covering several countries through the Madrid Protocol runs to a few thousand, depending on where you file. It renews about every ten years. Without it, most takedown routes are slower and weaker. (For the full picture, see the companion piece on what a hotel actually needs to trademark and what it costs.)

Build a Domain Portfolio Around Your Brand Name

Difficulty 3 / 10

Own the obvious variations before someone else does. Register your .com, the common misspellings, the hyphenated forms, and your country's ending (like .co.th in Thailand), then point them all to your real site with a simple redirect. A standard domain is about ten to twenty dollars a year, so the full set stays well under a few hundred a year. The hotel-specific endings are a dead end for most: .hotels is closed (Booking Holdings owns it), .hotel has restricted availability, and .travel is a premium, often $150 or more a year to renew. Skip those and cover the addresses a guest would actually mistype. This is the cheapest protection on the list.

Set Up SPF, DKIM, and DMARC Email Authentication

Difficulty 7 / 10

Email authentication (SPF, DKIM, and a DMARC policy set to reject) stops most attackers from sending mail that appears to come from a hotel's own domain. Without DMARC at enforcement, anyone can forge the hotel's sending domain, and a spam filter alone will not catch it.

These are three settings in your domain's DNS, the address system that tells the internet where your domain lives and how to handle its mail. Your email provider or IT team can add them.

  • SPF, Sender Policy Framework, lists the servers allowed to send mail as your domain.
  • DKIM, DomainKeys Identified Mail, adds a signature that proves a message really came from you and was not changed on the way.
  • DMARC, Domain-based Message Authentication, Reporting and Conformance, tells receiving mail systems what to do when a message fails those checks. It has three settings: none (watch only), quarantine (send to spam), and reject (refuse it). Only reject actually stops a forged email from reaching your guest. Many hotels have SPF and DKIM in place but leave DMARC at none, which is close to leaving it off.

This costs nothing but the time and expertise to set it up. It is the highest-value step you can take for your guests' inboxes. (Teaching your team to spot the phishing emails that slip through is a separate job, covered in our staff guide.)

Verify Your Site in Google Search Console

Difficulty 3 / 10

A hotel protects its brand search in two main ways: owning the obvious misspellings and TLD variants of its own name, and verifying its site in Google Search Console. Verification lets it see which pages rank for its brand queries and flag any it does not own. Trademark registration adds a formal basis to request removal when a lookalike site or ad infringes the name.

Google Search Console is a free tool from Google that shows how your site appears in search: which pages rank, and for which searches. Verifying your site takes a few minutes and one DNS entry or a file upload. Once you can see the brand searches sending people to you, a page ranking on your name that you do not recognize stands out. You can also submit your real pages to help your own site hold the top of a brand search. This is often why a copycat outranks you: you never built your own pages to compete for your name.

File a Trademark Complaint With Google Ads

Difficulty 6 / 10

A registered trademark lets a hotel file a trademark complaint with Google Ads, which restricts other advertisers from using the brand name in ad text, though not always from bidding on it as a keyword. It is one of the few brand-protection steps with a direct, enforceable channel built by the platform itself.

Once your trademark is registered, you record it with Google Ads at no cost. This stops other advertisers from putting your name in their ad text, which is what makes their ad look like yours. It does not always stop them from bidding on your name as a keyword, so a rival or an affiliate may still appear. Two responses help: run your own brand ad so you hold the top spot, and where an ad points to a site that copies you, use the trademark complaint together with the takedown steps below.

Put a Guest-Communication Policy in Writing

Difficulty 3 / 10

The simplest protection for your guests is telling them, in advance, what you will never do. Put one short paragraph in every booking confirmation and pre-arrival email. For example: "We will never email or call to ask for your card number, a password, or a photo of your ID. Every payment goes through our secure booking page at yourhotel.com. If an email asks for these, do not click any link in it. Forward it to [email protected] and we will confirm." A guest who has read that line twice is far harder to fool, and it gives your team a clear thing to point to.

Monitor for Brand Mentions and Impersonation Accounts

Difficulty 4 / 10

Brand-mention monitoring catches impersonation accounts while they still have low follower counts, before a guest engages with one expecting it to be real. It can be a paid tool, a manual weekly search of the hotel's name across the major platforms, or an outside service that watches it for you.

At the free end, set an alert on your name and its common misspellings, and once a week search your name on Instagram, Facebook, TikTok, and LinkedIn. Paid brand-monitoring tools run from roughly $80 a month at the entry level to several hundred for fuller coverage. Or include it in your Sorveil subscription. Either way, the point is to find a fake profile while it is new. Each platform has a route to report an account impersonating a business, and they act faster on a name backed by a registered trademark.

Protection measures at a glance

MeasureDifficultyWhat it stopsWho owns it
Trademark registration6 / 10Weak, slow takedowns with no legal basisNational trademark office filing (owner or lawyer)
Domain portfolio3 / 10Lookalike and misspelled domains registered against youWeb or IT team, through your registrar
SPF, DKIM, DMARC7 / 10Forged email sent from your own domainIT or email provider (needs DNS access)
Google Search Console3 / 10Blindness to which pages rank on your nameMarketing or web team
Google Ads trademark complaint6 / 10Competitors placing your name in ad textMarketing team, once the trademark exists
Guest-communication policy3 / 10Guests fooled by fake payment requestsReservations and front office
Brand-mention monitoring4 / 10Impersonation growing unseenMarketing, or an outside service

What this costs, and for whom. For a property at this level, none of the one-time steps here is a real expense. A trademark and a handful of domains cost almost nothing next to a single intercepted booking. The cost that adds up is the watching. Capable monitoring runs from tens to a few hundred dollars a month, and someone still has to read it every week and act on what it finds. That recurring cost and effort is where a hotel decides whether to run this in-house or hand it to a firm that does only this.

Closing the Leak: Protection, and the Direct Path Itself

The measures above stop the leak. They keep others from standing between your name and your guests. But stopping the leak is only half of winning direct bookings. The other half is the path a guest lands on once they do reach you: whether your own booking flow is easy, and whether the AI tools now planning trips point guests to you or to a reseller. Now that parity rewards direct pricing, that path is finally worth building properly. (We cover the technology that makes the direct path work in a companion piece, coming soon.)

New impostors appear over time. Someone can register a lookalike domain tomorrow, an affiliate can build a page on your name next week, and neither will announce itself. Keeping watch across your domain, your brand search, your ads, and your listings is ongoing work, which is what Sentinel does: continuous monitoring, so the first to know is you, not a guest with a fraudulent charge.

If you would like us to check what is currently operating under your hotel's name, start here.

What to Do If You Find a Clone Site or Fake Page Impersonating Your Hotel

If you find a clone site or a page impersonating your hotel, move on two tracks at once: report the site through every channel that can act on it, and, if you hold a trademark, start the process to claim or remove the domain.

How to Report a Phishing Website Impersonating Your Hotel

Difficulty 5 / 10

  1. Registrar abuse contact. A WHOIS lookup shows the registrar, the company that sold the domain. Send its abuse address (usually abuse@ the registrar) your evidence: the fake URL, screenshots, and your real site for comparison. The registrar abuse contact is the channel built for exactly this.
  2. Google Safe Browsing. Report the URL to Google Safe Browsing, the system that flags dangerous sites with a red warning in Chrome and other browsers. This protects guests even before the site comes down.
  3. Hosting-provider abuse. The company hosting the site also has an abuse address, which a WHOIS or hosting lookup will show. Send the same evidence.
  4. APWG. Forward the URL to the Anti-Phishing Working Group, an industry body that collects reports and feeds browser and email filters. The address is [email protected].
  5. DMCA or trademark complaint. Where the site copies your photos or your name, and you hold the rights, file a copyright (DMCA) or trademark complaint with the host and with Google. This is faster and stronger when your trademark is already registered.

Send the same evidence to each, and keep a record of what you sent and when.

How to Get a Lookalike Domain Taken Down

Difficulty 8 / 10

Taking a lookalike domain away from whoever registered it usually runs through the UDRP, the Uniform Domain-Name Dispute-Resolution Policy, a formal process for claiming a domain that copies a trademark in bad faith. Reporting can get a fraudulent page removed quickly. Taking the domain itself is the slower, more permanent route. You file with an approved provider, show that the domain matches your mark and was registered to trade on your name, and a panel decides. It works best with a registered trademark behind it. For a plain copy with fraud attached, the report channels above are faster. For a domain squatting on your name for the long term, UDRP is the route that ends it. If real money has already moved, or the same operator keeps returning, that is the point to bring in a lawyer.

Frequently Asked Questions

What is a hotel clone website?

A clone website copies a hotel's name, photos, and branding to rank in search or in ads, then routes the booking through an affiliate link or a fraudulent payment page instead of the hotel's own reservation system. Guests believe they booked directly with the hotel. The hotel never sees the reservation or keeps the margin.

What is OTA affiliate arbitrage?

Affiliate arbitrage is when a third party ranks content or buys ads against a hotel's own brand name, then reroutes the click through an OTA (online travel agency) affiliate link. The operator earns a commission on a booking the hotel would otherwise have received directly, at full rate. It targets hotels because rate-parity rules that used to block this have loosened, so direct-intent guests are newly profitable to intercept.

How can I tell if my hotel is being impersonated?

The clearest signal is a listing the hotel did not create, sitting above or beside its own site when someone searches the hotel's name. A second signal is a guest's booking confirmation priced or routed differently than the hotel's own direct rate. A hotel can check this in under five minutes by searching its own name from a signed-out browser and reading every result on page one.

How do I stop phishing emails sent from my hotel's domain?

Email authentication (SPF, DKIM, and a DMARC policy set to reject) stops most attackers from sending mail that appears to come from a hotel's own domain. Without DMARC at enforcement, anyone can forge the hotel's sending domain, and a spam filter alone will not catch it.

How do I report a fake site impersonating my hotel?

Report the fraudulent URL through four channels at once: the domain registrar's abuse contact (found with a WHOIS lookup), Google Safe Browsing, the hosting provider's abuse contact, and the Anti-Phishing Working Group at [email protected]. Where you hold a trademark, add a DMCA or trademark complaint to the host and to Google. Keep screenshots and a record of every report.

How do I protect my hotel's brand name in Google?

A hotel protects its brand search in two main ways: owning the obvious misspellings and TLD variants of its own name, and verifying its site in Google Search Console, which shows which pages rank for its brand queries. Trademark registration adds a formal basis to request removal when a lookalike site or ad infringes the name.

Sorveil
We see what you stopped seeing. Sorveil is a guest intelligence practice for luxury and upper-upscale hotels. Sentinel is our brand and booking protection service, independent and fee-only, with no tie to any OTA.

Back to Sightlines

See who is trading on your hotel's name.

We'll show you exactly what is operating under your name right now. In confidence, and with no obligation.

Get in touch

Or see how Sentinel keeps watch

Get in touch