Typosquatting is a domain-based attack where someone registers a misspelled or look-alike version of a legitimate domain, hoping you mistype the real one and land on theirs. Type goggle.com instead of google.com, and you might find a page that looks right but was built to steal your credentials. The technique is also called URL hijacking, and it is a form of cybersquatting.
The math is simple for an attacker. People type fast, phones make typos easy, and almost no one double-checks a URL before hitting enter. Typosquatters register domains that sit one keystroke away from a trusted brand, then wait for the traffic to arrive.
How Typosquatting Works
A typosquatting attack starts with registration. The attacker buys one or more domain names that resemble a legitimate website, swapping a letter, adding one, or changing the domain ending. These typosquatted domains cost a few dollars each, so an attacker can register dozens of variations of a single brand at once.
What happens next depends on the goal. Some typosquatted domains simply redirect visitors to ads or affiliate links for quick revenue. Others host a spoofed version of the real login page to harvest credentials and personal information, since a single stolen credential can be enough to compromise an account. The most dangerous push malware or ransomware to anyone who lands on them, sometimes without a single click.
Many of these domains sit dormant after registration, parked until the attacker decides to weaponize them. That is why monitoring parked domains matters, a quiet typosquatted domain today can become a live phishing page tomorrow.
Common Types of Typosquatting
Typosquatting is not one trick but a family of them, grouped by how the fake domain is built. Most fall into a few recognizable patterns.
- Misspellings, the classic form, where a single wrong or missing letter creates the fake domain, like goggle.com for google.com.
- Homoglyph attacks, which swap a letter for a look-alike character from another alphabet, so a Cyrillic character renders identically to a Latin one in the browser.
- Top-level domain (TLD) swaps, where the attacker keeps the name but changes the ending, registering the .net or .co version of a brand that uses .com, or buying the same name across other TLDs.
- Combosquatting, which joins the real name to an extra word with a hyphen, like brand-login.com or brand-support.com, since extra words in a domain rarely belong to the genuine brand.
- Subdomain spoofing, which buries the real brand name inside a longer URL so a hurried reader trusts it at a glance.
No single pattern dominates. A determined attacker registers several at once, casting a wide net so that almost any plausible mistype lands on a domain they control.
Common Typosquatting Examples
Typosquatting is easier to grasp through real-world examples. The most common scenario is a fake site that mirrors a real site almost exactly, built to trick users into entering a password on a screen they already trust.
- Credential theft, where attackers register domains that impersonate a bank or workplace portal and steal personal information from users who mistype a URL.
- Ad and affiliate fraud, where a typosquatting site serves a page full of ads or pop-up offers and earns money on every accidental visit.
- Malware delivery, where typosquatters send visitors to a malicious page and a single click, or even a silent drive-by download, installs malicious code.
- Brand abuse, where lookalike domains damage a company’s reputation and enable identity theft against its customers.
These dangers scale with the brand. Attackers register misspelled domain names by the dozen, each a slightly different address pointing to the same malicious destination.
Typosquatting vs. Cybersquatting and Domain Hijacking
These terms get used interchangeably, but they describe different attacks. Cybersquatting is the broad practice of registering domains tied to someone else’s trademark in bad faith. Typosquatting is the subset that targets typos and misspelled URLs specifically.
Domain hijacking is different again. There, an attacker takes control of a domain you already own, usually by compromising your registrar account, rather than registering a look-alike. Our guide to domain hijacking covers that threat in full. Typosquatting requires no access to your systems at all, which is part of what makes it so common.
Why Typosquatting Keeps Working
Typosquatting survives on human habit. We prioritize speed over accuracy when we type a URL, and a domain that is off by one character looks right at a glance. On a small phone screen, the difference between a legitimate site and a malicious one can be a single pixel.
Scale makes it worse. Registering a domain takes minutes and costs almost nothing, so typosquatters can blanket every plausible variation of a popular brand. Add in look-alike characters and long URLs, and even careful users get fooled. Attackers use typosquatting precisely because of its low cost — one of the cheapest attack techniques to run, and one that pays off as long as people keep mistyping.
How to Detect and Prevent Typosquatting
You cannot stop people from registering look-alike domains, but you can shrink the damage they do. Defense works on two fronts: your own brand and your users.
- Register the obvious variations yourself, common misspellings and the main top-level domains, so attackers cannot grab them first.
- Monitor for new typosquatted domains using certificate transparency logs, threat feeds, and open-source intelligence, and act fast when one appears.
- Harden email infrastructure with Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC), so a spoofed domain cannot send mail that looks like yours.
- Train people to slow down, check the address bar, and treat unexpected login pages with suspicion.
- Layer in DNS filtering and antivirus so a known malicious site is blocked before it loads.
No single step is enough on its own. The organizations that handle typosquatting well treat it as continuous security work, pairing domain monitoring with user awareness so a stray click does not become the first step of a phishing attack.
Legal Recourse Against Typosquatters
Prevention shrinks your exposure, but you can pursue typosquatters directly. In the United States, the Anticybersquatting Consumer Protection Act (ACPA) lets trademark owners take legal action against cybersquatters who profit from a confusingly similar name. Registering a domain in bad faith to trade on a brand is exactly what the ACPA was written to stop.
There is an international route too. The World Intellectual Property Organization runs a dispute process that can transfer or cancel an offending domain without a full court case. Neither path is instant, so most organizations treat takedowns as one layer among several, paired with the monitoring that finds these domains in the first place.
How SecurityScorecard Helps You Stay Ahead of Typosquatting
Spotting a typosquatted domain before it is weaponized takes constant visibility into newly registered domains across the internet. SecurityScorecard scans 4.1 billion IP addresses and domains every week, using WHOIS (domain registration data), DNS records, and web crawling to flag look-alike and parked domains across both your own footprint and your vendors’.
Our STRIKE threat intelligence team tracks these campaigns in the wild. In one investigation, STRIKE traced an attacker who registered nobelform[.]com to spoof NobleForms, a legitimate company, as part of a broader phishing operation. That kind of attribution turns a suspicious domain name into an actionable warning.
TITAN AI folds this domain intelligence into third-party risk, so a typosquatted domain impersonating one of your vendors surfaces as a prioritized alert, helping you protect your organization before its customers get hit. For teams that want monitoring and takedown support handled on their behalf, our TITAN MAX managed services run it as an extension of your security team. Request a demo to see how we catch look-alike domains early.