undoppel

Brand protection guide

What Is Typosquatting? How Lookalike Domains Attack Your Brand

**Typosquatting** is the practice of registering domain names that closely resemble a legitimate brand's domain — usually by exploiting common typing…

What Is Typosquatting?

Typosquatting is the practice of registering domain names that closely resemble a legitimate brand's domain — usually by exploiting common typing mistakes — to intercept misdirected traffic, deceive users, or impersonate the brand. A visitor aiming for example.com might type "exemple.com" or "example.co" and land on a site controlled by an attacker instead.

Also called URL hijacking or brand impersonation via lookalike domains, typosquatting works because humans mistype, misread, and trust domains that look "close enough." Attackers monetize that gap through ad pages, phishing, malware delivery, or credential theft.

How Typosquatting Works

The mechanism is simple: register a domain a real user might reach by accident or be tricked into trusting, then do something profitable with the traffic. The registration itself is cheap and instant, and a single brand can be surrounded by hundreds of plausible variants.

Once a lookalike domain is live, an attacker typically pairs it with supporting infrastructure that makes the deception convincing:

Because certificates are logged publicly the moment they're issued, and DNS records are queryable, these setups leave a trail — which is exactly what monitoring is built to catch early.

The Main Types of Typosquatting

Typosquatting isn't one trick. It's a family of techniques, and defending your brand means knowing all of them.

Character substitution and typos

The classic form: swapping, dropping, doubling, or transposing characters that sit near each other on a keyboard. Think "exmaple.com" (transposition), "exampl.com" (omission), or "exampple.com" (insertion). Adjacent-key errors like "wxample.com" are common because attackers model real fat-finger patterns.

Homoglyphs and IDN attacks

Homoglyph attacks replace a character with one that looks nearly identical. A lowercase "l" swapped for a capital "I," or a zero for the letter "O." Internationalized Domain Names (IDN) make this worse: Unicode contains Cyrillic and Greek letters that render identically to Latin ones. A domain using a Cyrillic "а" can look pixel-for-pixel like "example.com" while being a completely different registration. These are the hardest lookalikes to catch by eye.

TLD swaps

Same brand name, different extension. If you own example.com, an attacker grabs example.net, example.co, example.io, or a country-code TLD like example.com.co. Users rarely scrutinize the ending of a domain, making TLD swaps highly effective for both phishing and reputation attacks.

Combosquatting

Instead of misspelling your name, combosquatting appends a plausible keyword: "example-login.com," "example-support.com," "secure-example.net," or "example-billing.com." The brand name is spelled correctly, which makes these feel legitimate — and there are effectively unlimited combinations.

Subdomain and path tricks

Attackers structure a URL so the brand appears where users expect it while the real registered domain is something else entirely. "example.com.login-secure.net" reads left-to-right as "example.com" but is actually a subdomain of the attacker's "login-secure.net." On mobile, where the address bar truncates, this is especially deceptive.

Why Typosquatting Succeeds

Understanding the psychology and infrastructure gaps helps you prioritize defenses.

What Attackers Do With Lookalike Domains

The registration is only the setup. The damage comes from how the domain is used:

  1. Phishing and credential theft — a fake login page that captures usernames and passwords, then forwards them to your real site so the victim notices nothing.
  2. Business email compromise (BEC) — email sent from a lookalike domain to your customers, vendors, or staff requesting payment or sensitive data.
  3. Malware distribution — mistyped domains that trigger drive-by downloads or fake "update" prompts.
  4. Ad revenue and traffic theft — parked pages monetizing your misdirected visitors, sometimes redirecting them to competitors.
  5. Brand damage and scams — counterfeit storefronts or fake support lines that erode customer trust in your real brand.

How to Spot a Typosquatting Domain

You can catch many lookalikes with a disciplined eye. Use this checklist when a domain seems off:

The catch: manual inspection only helps for domains you happen tosee. You can't eyeball hundreds of permutations across dozens of TLDs, and homoglyph or IDN variants are designed to defeat exactly this kind of visual check. That's why detection has to be systematic rather than manual.

How to Prevent and Defend Against Typosquatting

A layered defense combines a few things you do yourself with continuous monitoring that does the heavy lifting for you.

The last point is where most brands fall behind. New typosquat domains appear constantly, complete with fresh TLS certificates and MX records, and the window between registration and an active phishing campaign is short. Manual checks can't keep pace.

Let Undoppel Find Your Lookalike Domains

Instead of guessing which variants exist, run a free brand scan at undoppel.io. Undoppel generates the full range of typosquat permutations for your brand — character substitutions, homoglyph and IDN lookalikes, TLD swaps, and combosquatting patterns — then checks which ones are actually registered, whether they carry active DNS and MX records, and whether new certificates for them appear in certificate transparency logs. That turns an impossible manual task into a single view of your real exposure, with ongoing monitoring so you're alerted the moment a new lookalike goes live.

Enter your domain at undoppel.io and see which typosquatting domains are already targeting your brand today.

Is your brand being impersonated?

Run a free instant scan for typosquats and lookalike domains targeting your brand.

Run a free brand scan →