A convincing imitation of your company costs an attacker a domain registration and an afternoon. The variants that matter are the ones a customer would not scrutinise: a hyphen added, a letter doubled, a different top-level domain, a homoglyph from another script.
Defensive registration of every possible variant is not affordable and not necessary. Register the handful a customer might plausibly type — the common misspellings, the obvious alternate extensions, the singular and plural — and point them at your real site. Beyond that, monitoring beats ownership.
Monitoring is available cheaply. Certificate transparency logs record every certificate issued for every domain, publicly, and free services will alert you when one is issued for a name resembling yours. That is often the earliest warning that a phishing site is being prepared, because the certificate is obtained before the campaign starts.
Email is the channel most often abused. Publishing SPF, DKIM and a DMARC policy set to reject means receiving servers discard mail that forges your domain. Many organisations publish DMARC in monitoring mode and never move to enforcement, which produces reports nobody reads and stops nothing.
For India, a registered trademark materially strengthens your position. It gives you standing in domain dispute proceedings and makes takedown requests to platforms and hosts far more likely to succeed. Without it, a complaint about a lookalike is a request; with it, it is a claim.
Give customers a way to check. A page listing your official domains, social accounts and the addresses you send from costs nothing, and it gives your support team something to point at when a customer asks whether a message is genuine. That question arrives more often than most companies expect.