dokyma

Brand protection guide

What Is Typosquatting? How Lookalike Domains Attack Your Brand

**Typosquatting** is the practice of registering domain names that closely resemble a legitimate brand's domain — usually by exploiting common typing…

What Is Typosquatting?

Typosquatting is the practice of registering domain names that closely resemble a legitimate brand's domain — usually by exploiting common typing mistakes — to capture misdirected traffic, impersonate the brand, or launch phishing and fraud. If your real site is example.com, a typosquatter might register exmaple.com, exampl.com, or example.co, betting that a slice of your visitors will land there by accident.

These are sometimes called lookalike domains or cousin domains, and they power everything from ad-revenue scams to credential theft and invoice fraud. The attack works because humans mistype URLs, misread characters, and trust anything that looks close enough to the real thing.

How Typosquatting Works

Attackers don't guess randomly. They generate hundreds of plausible variations of a target domain, register the ones most likely to fool people, and then point them at infrastructure designed to profit. The lifecycle usually looks like this:

  1. Permutation — Generate variants of the brand name using predictable patterns (see the techniques below).
  2. Registration — Buy the most convincing ones, often through privacy-shielded registrars that hide ownership.
  3. Weaponization — Set up a landing page, a phishing clone, a mail server, or a redirect.
  4. Monetization — Steal logins, run ad networks, intercept email, or resell the domain to the brand at a markup.

A registered lookalike domain becomes dangerous the moment it gains two things: a TLS certificate (the padlock that makes it look secure) and MX records (mail servers that let it send email as your brand). Either one signals the domain is being prepared for active abuse rather than sitting idle.

The Main Typosquatting Techniques

Typosquatting is a family of tricks, not a single move. Recognizing the categories helps you understand the full attack surface:

Combosquatting and homoglyph attacks are the hardest for people to catch because there's no obvious misspelling — the deception lives in structure or invisible character encoding.

Why Typosquatting Succeeds

The attack exploits trust and inattention, not technical vulnerabilities. A few reasons it keeps working:

How Typosquatting Is Used Against Your Brand

The registered lookalike is just the container. What attackers do with it determines the damage:

How to Spot a Typosquatting Domain

Use this checklist to evaluate a suspicious domain:

  1. Read the domain right to left. The true owner is whatever sits just before the TLD. example.com.evil.net belongs to evil.net, not you.
  2. Check for character swaps and doubles. Compare letter by letter against your real domain — don't trust your first glance.
  3. Look for non-Latin characters. IDN homoglyph domains often display a warning or an unusual "xn--" prefix in the raw address.
  4. Inspect the TLD. A brand you know as .com suddenly appearing on .co, .info, or an obscure extension is a red flag.
  5. Watch for appended keywords. "-secure," "-login," "-support," "-verify," and "-account" are combosquatting staples.
  6. Verify certificate and mail activity. A lookalike that has recently obtained a TLS certificate or configured mail servers is being actively armed for an attack, not sitting harmlessly parked.

Checking WHOIS ownership, DNS and MX records, TLS certificates, and certificate transparency logs by hand — across every possible permutation of your brand — is impractical. That discovery and monitoring work is exactly what a Dokyma scan does for you automatically.

How to Defend Your Brand Against Typosquatting

Prevention and detection work together. A few defensive steps are worth doing yourself:

Those steps shrink the attack surface, but they don't tell you which hostile lookalikes already exist or when a new one gets registered and armed. That's the detection gap.

Find the Lookalike Domains Targeting You Today

The registrations that hurt you are the ones you don't know about — the homoglyph clone with a fresh TLS certificate, the combosquat with live mail servers, the TLD swap already redirecting your traffic. Run a free brand scan at dokyma.com to see which typosquatting and lookalike domains already exist for your brand, which ones are configured to send email or serve pages, and which need action first. Start with your primary domain and let the scan surface the variants working against you right now.

Is your brand being impersonated?

Run a free instant scan for typosquats and lookalike domains targeting your brand.

Run a free brand scan →