What Is Typosquatting?
Typosquatting is the practice of registering domain names that closely resemble a legitimate brand's domain — usually by exploiting common typing mistakes — to intercept misdirected traffic, deceive users, or impersonate the brand. A visitor aiming for example.com might type "exemple.com" or "example.co" and land on a site controlled by an attacker instead.
Also called URL hijacking or brand impersonation via lookalike domains, typosquatting works because humans mistype, misread, and trust domains that look "close enough." Attackers monetize that gap through ad pages, phishing, malware delivery, or credential theft.
How Typosquatting Works
The mechanism is simple: register a domain a real user might reach by accident or be tricked into trusting, then do something profitable with the traffic. The registration itself is cheap and instant, and a single brand can be surrounded by hundreds of plausible variants.
Once a lookalike domain is live, an attacker typically pairs it with supporting infrastructure that makes the deception convincing:
- MX records so the domain can send and receive email — the foundation for phishing and business email compromise.
- A TLS certificate so the fake site loads over HTTPS with a padlock, defeating the "look for the lock" advice most users still follow.
- A cloned or parked page that mirrors your login screen, checkout, or brand design to harvest credentials or payments.
Because certificates are logged publicly the moment they're issued, and DNS records are queryable, these setups leave a trail — which is exactly what monitoring is built to catch early.
The Main Types of Typosquatting
Typosquatting isn't one trick. It's a family of techniques, and defending your brand means knowing all of them.
Character substitution and typos
The classic form: swapping, dropping, doubling, or transposing characters that sit near each other on a keyboard. Think "exmaple.com" (transposition), "exampl.com" (omission), or "exampple.com" (insertion). Adjacent-key errors like "wxample.com" are common because attackers model real fat-finger patterns.
Homoglyphs and IDN attacks
Homoglyph attacks replace a character with one that looks nearly identical. A lowercase "l" swapped for a capital "I," or a zero for the letter "O." Internationalized Domain Names (IDN) make this worse: Unicode contains Cyrillic and Greek letters that render identically to Latin ones. A domain using a Cyrillic "а" can look pixel-for-pixel like "example.com" while being a completely different registration. These are the hardest lookalikes to catch by eye.
TLD swaps
Same brand name, different extension. If you own example.com, an attacker grabs example.net, example.co, example.io, or a country-code TLD like example.com.co. Users rarely scrutinize the ending of a domain, making TLD swaps highly effective for both phishing and reputation attacks.
Combosquatting
Instead of misspelling your name, combosquatting appends a plausible keyword: "example-login.com," "example-support.com," "secure-example.net," or "example-billing.com." The brand name is spelled correctly, which makes these feel legitimate — and there are effectively unlimited combinations.
Subdomain and path tricks
Attackers structure a URL so the brand appears where users expect it while the real registered domain is something else entirely. "example.com.login-secure.net" reads left-to-right as "example.com" but is actually a subdomain of the attacker's "login-secure.net." On mobile, where the address bar truncates, this is especially deceptive.
Why Typosquatting Succeeds
Understanding the psychology and infrastructure gaps helps you prioritize defenses.
- Users read shapes, not strings. People recognize the silhouette of a familiar domain and don't parse it character by character.
- Registration is unregulated at scale. Nothing stops anyone from registering a near-copy of your domain until you or a monitoring service flags it.
- Trust signals are borrowed. HTTPS padlocks, copied logos, and even functioning email make a fake domain feel authentic.
- Detection is asymmetric. An attacker needs one successful variant; you need visibility into all of them at once.
What Attackers Do With Lookalike Domains
The registration is only the setup. The damage comes from how the domain is used:
- Phishing and credential theft — a fake login page that captures usernames and passwords, then forwards them to your real site so the victim notices nothing.
- Business email compromise (BEC) — email sent from a lookalike domain to your customers, vendors, or staff requesting payment or sensitive data.
- Malware distribution — mistyped domains that trigger drive-by downloads or fake "update" prompts.
- Ad revenue and traffic theft — parked pages monetizing your misdirected visitors, sometimes redirecting them to competitors.
- Brand damage and scams — counterfeit storefronts or fake support lines that erode customer trust in your real brand.
How to Spot a Typosquatting Domain
You can catch many lookalikes with a disciplined eye. Use this checklist when a domain seems off:
- Read the domain right-to-left starting from the TLD, and confirm the registered domain (the part just before the extension) is truly yours.
- Check for character swaps — zeros for O's, "rn" that reads as "m," capital I for lowercase l.
- Watch for extra words or hyphens appended to your brand name (combosquatting).
- Be suspicious of unfamiliar TLDs carrying your exact brand name.
- Hover before clicking in emails to reveal the true destination, and don't trust the display text.
- Treat a valid HTTPS padlock as meaningless for authenticity — anyone can get a certificate for a lookalike domain.
The catch: manual inspection only helps for domains you happen tosee. You can't eyeball hundreds of permutations across dozens of TLDs, and homoglyph or IDN variants are designed to defeat exactly this kind of visual check. That's why detection has to be systematic rather than manual.
How to Prevent and Defend Against Typosquatting
A layered defense combines a few things you do yourself with continuous monitoring that does the heavy lifting for you.
- Register your highest-risk variants — the common misspellings, the major TLDs (.com, .net, .org, .co), and obvious combosquat patterns like "brand-login." You can't buy every permutation, but owning the most likely ones removes the easiest targets.
- Lock down your own email authentication. Configure SPF, DKIM, and DMARC on your real domain so attackers can't spoof it directly and are forced onto lookalikes — which are easier to spot and take down.
- Educate staff and customers on verifying the exact domain and never trusting the padlock alone.
- Monitor continuously for new lookalikes as they're registered, because the threat is created after you've secured your own domains, not before.
The last point is where most brands fall behind. New typosquat domains appear constantly, complete with fresh TLS certificates and MX records, and the window between registration and an active phishing campaign is short. Manual checks can't keep pace.
Let Undoppel Find Your Lookalike Domains
Instead of guessing which variants exist, run a free brand scan at undoppel.io. Undoppel generates the full range of typosquat permutations for your brand — character substitutions, homoglyph and IDN lookalikes, TLD swaps, and combosquatting patterns — then checks which ones are actually registered, whether they carry active DNS and MX records, and whether new certificates for them appear in certificate transparency logs. That turns an impossible manual task into a single view of your real exposure, with ongoing monitoring so you're alerted the moment a new lookalike goes live.
Enter your domain at undoppel.io and see which typosquatting domains are already targeting your brand today.