Skip to content

What is typosquatting?

Updated October 4, 2026

Typosquatting is the practice of registering domain names that imitate a brand's domain through typing errors, misspellings, or visually similar characters, typically to divert traffic, display ads, deliver malware, or steal credentials.

UDRP cases filed in 2025
6,282, a record year (WIPO)
Estimated typo share of .com
~20% of registrations (USENIX 2014)
ACPA statutory damages
$1,000 to $100,000 per domain

The name comes from “typo” plus “squatting”: squatting on the mistakes people make when typing a web address. A typosquatted domain usually differs from the real one by a single character, a swapped pair of letters, an added hyphen, or a different extension. Because domain registration is cheap and fast, attackers register these variants in bulk and wait for the traffic to arrive on its own.

Typosquatting is a subset of the broader category of cybersquatting, which covers any bad-faith registration of a domain that targets someone else’s trademark. What makes typosquatting distinct is the mechanism: it harvests navigation errors rather than impersonating the brand outright, which means it works even against brands most people have never heard of.

The most common typosquatting techniques

The Center for Internet Security catalogs six core variations: omission, addition, substitution, transposition, hyphenation, and homoglyph. The misspelling row below folds substitution and transposition together; the remaining rows are the closely related variants that defenders treat the same way. Real-world squatters usually combine several. The examples use notolens.com as the target; the same patterns apply to any brand.

Technique Example What it exploits
Omission ntolens.com A dropped character in fast typing
Addition notolenss.com A doubled or extra character
Misspelling notolems.com An adjacent-key, substituted, or transposed letter
Pluralization notolenses.com A singular or plural suffix added or dropped
Hyphenation noto-lens.com A plausible hyphen split in a compound name
Homoglyph (IDN) notоlens.com A lookalike character from another script, such as Cyrillic о (U+043E) for Latin o (U+006F)
TLD swap notolens.shop The same name under a different extension
Combosquatting notolens-login.com The brand plus a plausible suffix like “login” or “support”
Bitsquatting jotolens.com A memory bit-flip that mutates a queried name
Vowel swap notolans.com A swapped vowel that still reads and sounds plausible

Homoglyph variants deserve a special note. Internationalized domain names allow characters from scripts like Cyrillic and Greek that render identically to Latin letters in most fonts. MITRE ATT&CK documents these IDN homograph attacks as a standard technique for standing up phishing and malware infrastructure. They are invisible to anyone who checks spelling rather than underlying code points. You can enumerate every variant of your own domain with the lookalike domain generator.

IDN homograph attacks: the typo nobody types

Homoglyphs break the one defense people trust most: reading the address. Internationalized domain names allow letters from scripts like Cyrillic and Greek, and many of them render identically to Latin letters in the address bar. A notolens.com spelled with a Cyrillic о is a different registration held by someone else that looks exactly right.

The tell lives in the encoding. DNS stores these names in Punycode, a syntax that prefixes the label with xn--. The raw form reveals the substitution, but almost nobody inspects raw domains. That is why Unicode’s own security report, UTR #36, treats confusable characters as a standing risk, and why some registries restrict mixed-script labels. Coverage is patchy, though, and a single swapped character is often enough.

Defense has to work on the raw name, not the rendered one. notolens decodes internationalized candidates before matching, so a Cyrillic swap surfaces in your inbox the same way a plain typo would.

How typosquatters make money

Measurement research finds that most typosquatted domains carry pay-per-click advertising: the mistyped visitor sees a page of ads, often including ads for the real brand, and the squatter collects a fraction of a cent per visit at scale. The remaining minority is where the damage concentrates:

  • Phishing and credential theft. A pixel-perfect copy of a sign-in page that posts credentials elsewhere. Combosquatted names like brand-login.com exist largely for this purpose.
  • Malware delivery. Drive-by downloads and fake software updates, a technique tracked in MITRE ATT&CK as T1583.001.
  • Traffic and affiliate redirect. Sending the visitor to a competitor or an affiliate checkout to capture the intended purchase.
  • Resale. Offering to sell the domain back to the brand owner, which US law treats as a textbook indicator of bad faith.
  • Mail interception. A lookalike domain with MX records can receive misaddressed email, a quiet channel for invoice fraud and business email compromise.

A parked page today is not proof the domain is harmless. The same measurement work found squatters routinely change monetization strategy over time, and a domain that lapses can be re-registered by a different operator later.

Why small brands are targets too

The largest measurement study of the .com zone (Szurdi et al., USENIX Security 2014) estimated that roughly 20% of all .com registrations were typo domains, and found that only 6.8% of them targeted the 10,000 most popular sites. The remaining 93% targeted the long tail: mid-size and small brands that are less likely to monitor for abuse.

The raw material is enormous. Verisign reported 386.9 million domain registrations across all TLDs at the end of 2025, with 10.7 million new .com and .net names registered in Q4 2025 alone. Nobody can check that volume by hand; even the biggest brands only see the variants that surface through complaints or monitoring.

The consequences show up in crime statistics. The FBI’s IC3 received 193,407 phishing and spoofing complaints in 2024, making it the single most reported crime type, and total reported losses reached $16.6 billion. WIPO trademark holders filed a record 6,282 domain dispute cases in 2025, bringing the total since 1999 to over 80,000 cases covering more than 143,000 domain names.

Typosquatting vs. cybersquatting

The terms overlap but are not interchangeable. Cybersquatting covers the general practice of registering domains that target someone else’s trademark for profit, for example registering a competitor’s product name hoping to resell it. Typosquatting is the narrower tactic built on typing errors and visual similarity. Both fall under the same legal frameworks: the UDRP treats confusingly similar registrations as abusive, and the ACPA covers any domain “identical or confusingly similar” to a protected mark, typo variants included.

Three mechanisms cover most situations, from cheapest to most formal:

  • Registrar and hosting abuse reports. When a lookalike is actively phishing or distributing malware, providers suspend it under their acceptable use policies. Our guides cover reporting domain abuse to a registrar and reporting hosting abuse step by step.
  • UDRP complaint. ICANN’s administrative process lets a trademark owner recover a domain by proving confusing similarity, no legitimate interest, and bad-faith registration and use. Remedies are transfer or cancellation, and decisions typically arrive within 45 to 60 days. See how to file a UDRP domain dispute.
  • ACPA litigation. In US federal court, the Anticybersquatting Consumer Protection Act allows statutory damages of $1,000 to $100,000 per domain, plus forfeiture or transfer. Its in rem provision lets a court act on the domain itself when the registrant cannot be identified or reached, which matters because squatters routinely hide behind privacy services.

None of these require proving the squatter’s intent at detection time. What they all reward is documentation: dated registration records, screenshots, DNS evidence, and a clear timeline of when the domain appeared and what it showed.

How to catch typosquats early

Typosquatting is a volume game on both sides. The attacker registers hundreds of candidates cheaply; the defender’s job is to see each new one the day it appears, not after a customer reports a scam.

A one-off search shows what exists today. Domain monitoring watches the daily stream of new registrations and flags variants the day they are registered, while there is still time to act before the domain is weaponized. Watching the registration stream also catches the dormant pattern: a domain parked harmlessly for months that suddenly starts serving a phishing kit.

For a point-in-time view, the domain watch report shows every lookalike registration of your brand from the last 30 days, and the lookalike domain generator enumerates the variant space an attacker would choose from.

Sources

Frequently asked questions

Related tools and resources

Catch typosquats the day they register.

notolens checks every new registration against your brand, scores and explains the risk, and keeps the records you need for a report or dispute. Clear monthly pricing, no sales calls.

Start monitoring in 3 minutes