What Is Typosquatting?
Typosquatting is the practice of registering domain names that closely resemble a legitimate brand's domain — usually by exploiting common typing mistakes — to capture misdirected traffic, impersonate the brand, or launch phishing and fraud. If your real site is example.com, a typosquatter might register exmaple.com, exampl.com, or example.co, betting that a slice of your visitors will land there by accident.
These are sometimes called lookalike domains or cousin domains, and they power everything from ad-revenue scams to credential theft and invoice fraud. The attack works because humans mistype URLs, misread characters, and trust anything that looks close enough to the real thing.
How Typosquatting Works
Attackers don't guess randomly. They generate hundreds of plausible variations of a target domain, register the ones most likely to fool people, and then point them at infrastructure designed to profit. The lifecycle usually looks like this:
- Permutation — Generate variants of the brand name using predictable patterns (see the techniques below).
- Registration — Buy the most convincing ones, often through privacy-shielded registrars that hide ownership.
- Weaponization — Set up a landing page, a phishing clone, a mail server, or a redirect.
- Monetization — Steal logins, run ad networks, intercept email, or resell the domain to the brand at a markup.
A registered lookalike domain becomes dangerous the moment it gains two things: a TLS certificate (the padlock that makes it look secure) and MX records (mail servers that let it send email as your brand). Either one signals the domain is being prepared for active abuse rather than sitting idle.
The Main Typosquatting Techniques
Typosquatting is a family of tricks, not a single move. Recognizing the categories helps you understand the full attack surface:
- Character substitution — Swapping visually or physically similar keys: example.com becomes exanple.com or exampie.com (lowercase L vs. capital I).
- Character omission and duplication — Dropping or doubling a letter: exmple.com, exampple.com.
- Transposition — Reversing adjacent letters: exmaple.com.
- Homoglyphs and IDN attacks — Using non-Latin Unicode characters that render identically to Latin ones. A Cyrillic "а" looks exactly like a Latin "a," producing a domain that is visually indistinguishable from the real one.
- TLD swaps — Keeping the name but changing the extension: example.com becomes example.net, example.org, example.co, or a cheap new gTLD.
- Combosquatting — Appending real-looking words: example-login.com, example-support.com, secure-example.com. No typo required — the brand name is spelled correctly, which makes these especially convincing.
- Subdomain tricks — Structuring a hostile domain so the brand appears in the subdomain: example.com.login-verify.net. A hurried reader sees "example.com" and stops reading.
- Hyphenation and spacing — Adding or removing hyphens: ex-ample.com, exampleinc.com.
Combosquatting and homoglyph attacks are the hardest for people to catch because there's no obvious misspelling — the deception lives in structure or invisible character encoding.
Why Typosquatting Succeeds
The attack exploits trust and inattention, not technical vulnerabilities. A few reasons it keeps working:
- Domains are cheap and plentiful. Registering dozens of variants costs little compared to the payoff of one successful phishing campaign.
- Visual trust is fragile. Most people scan a URL, they don't parse it. A padlock icon and a familiar name are enough for the average user to enter a password.
- Email spoofing amplifies reach. A lookalike domain with valid mail records can send invoices or password-reset emails that pass basic authentication checks, because they genuinely come from a domain the attacker controls.
- Brands rarely watch their perimeter. Companies protect their own domain but almost never monitor the space of everything that resembles it — so hostile registrations go unnoticed for months.
How Typosquatting Is Used Against Your Brand
The registered lookalike is just the container. What attackers do with it determines the damage:
- Credential phishing — A pixel-perfect clone of your login page harvests usernames and passwords, often protected by TLS to look legitimate.
- Business email compromise — Using the lookalike's mail server to send fake invoices or wire-transfer requests to your customers and vendors.
- Malware distribution — Fake download or update pages serving malicious files under your brand's name.
- Ad and affiliate fraud — Parked pages loaded with ads or redirects that monetize your mistyped traffic.
- Reputation and SEO damage — Scam or adult content hosted on a domain the public associates with you.
- Extortion — Registering your variants and offering to sell them back, or simply squatting to block your expansion.
How to Spot a Typosquatting Domain
Use this checklist to evaluate a suspicious domain:
- Read the domain right to left. The true owner is whatever sits just before the TLD. example.com.evil.net belongs to evil.net, not you.
- Check for character swaps and doubles. Compare letter by letter against your real domain — don't trust your first glance.
- Look for non-Latin characters. IDN homoglyph domains often display a warning or an unusual "xn--" prefix in the raw address.
- Inspect the TLD. A brand you know as .com suddenly appearing on .co, .info, or an obscure extension is a red flag.
- Watch for appended keywords. "-secure," "-login," "-support," "-verify," and "-account" are combosquatting staples.
- Verify certificate and mail activity. A lookalike that has recently obtained a TLS certificate or configured mail servers is being actively armed for an attack, not sitting harmlessly parked.
Checking WHOIS ownership, DNS and MX records, TLS certificates, and certificate transparency logs by hand — across every possible permutation of your brand — is impractical. That discovery and monitoring work is exactly what a Dokyma scan does for you automatically.
How to Defend Your Brand Against Typosquatting
Prevention and detection work together. A few defensive steps are worth doing yourself:
- Register your highest-risk variants. Buy the obvious typos, key TLD swaps (.net, .org, .co), and common combosquat forms before someone else does. You can't own every variation, but you can take the most dangerous ones off the market.
- Lock down email authentication. Publish SPF, DKIM, and a strict DMARC policy so mail providers reject spoofed messages claiming to be from your real domain.
- Educate customers and staff. Tell people the exact domains you use and that you never request credentials or payment changes by email link.
Those steps shrink the attack surface, but they don't tell you which hostile lookalikes already exist or when a new one gets registered and armed. That's the detection gap.
Find the Lookalike Domains Targeting You Today
The registrations that hurt you are the ones you don't know about — the homoglyph clone with a fresh TLS certificate, the combosquat with live mail servers, the TLD swap already redirecting your traffic. Run a free brand scan at dokyma.com to see which typosquatting and lookalike domains already exist for your brand, which ones are configured to send email or serve pages, and which need action first. Start with your primary domain and let the scan surface the variants working against you right now.