What is typosquatting?
Updated October 4, 2026
Typosquatting is the practice of registering domain names that imitate a brand's domain through typing errors, misspellings, or visually similar characters, typically to divert traffic, display ads, deliver malware, or steal credentials.
- UDRP cases filed in 2025
- 6,282, a record year (WIPO)
- Estimated typo share of .com
- ~20% of registrations (USENIX 2014)
- ACPA statutory damages
- $1,000 to $100,000 per domain
The name comes from “typo” plus “squatting”: squatting on the mistakes people make when typing a web address. A typosquatted domain usually differs from the real one by a single character, a swapped pair of letters, an added hyphen, or a different extension. Because domain registration is cheap and fast, attackers register these variants in bulk and wait for the traffic to arrive on its own.
Typosquatting is a subset of the broader category of cybersquatting, which covers any bad-faith registration of a domain that targets someone else’s trademark. What makes typosquatting distinct is the mechanism: it harvests navigation errors rather than impersonating the brand outright, which means it works even against brands most people have never heard of.
The most common typosquatting techniques
The Center for Internet Security catalogs six core variations: omission, addition, substitution, transposition, hyphenation, and homoglyph. The misspelling row below folds substitution and transposition together; the remaining rows are the closely related variants that defenders treat the same way. Real-world squatters usually combine several. The examples use notolens.com as the target; the same patterns apply to any brand.
| Technique | Example | What it exploits |
|---|---|---|
| Omission | ntolens.com |
A dropped character in fast typing |
| Addition | notolenss.com |
A doubled or extra character |
| Misspelling | notolems.com |
An adjacent-key, substituted, or transposed letter |
| Pluralization | notolenses.com |
A singular or plural suffix added or dropped |
| Hyphenation | noto-lens.com |
A plausible hyphen split in a compound name |
| Homoglyph (IDN) | notоlens.com |
A lookalike character from another script, such as Cyrillic о (U+043E) for Latin o (U+006F) |
| TLD swap | notolens.shop |
The same name under a different extension |
| Combosquatting | notolens-login.com |
The brand plus a plausible suffix like “login” or “support” |
| Bitsquatting | jotolens.com |
A memory bit-flip that mutates a queried name |
| Vowel swap | notolans.com |
A swapped vowel that still reads and sounds plausible |
Homoglyph variants deserve a special note. Internationalized domain names allow characters from scripts like Cyrillic and Greek that render identically to Latin letters in most fonts. MITRE ATT&CK documents these IDN homograph attacks as a standard technique for standing up phishing and malware infrastructure. They are invisible to anyone who checks spelling rather than underlying code points. You can enumerate every variant of your own domain with the lookalike domain generator.
IDN homograph attacks: the typo nobody types
Homoglyphs break the one defense people trust most: reading the address. Internationalized domain names allow letters from scripts like Cyrillic and Greek, and many of them render identically to Latin letters in the address bar. A notolens.com spelled with a Cyrillic о is a different registration held by someone else that looks exactly right.
The tell lives in the encoding. DNS stores these names in Punycode, a syntax that prefixes the label with xn--. The raw form reveals the substitution, but almost nobody inspects raw domains. That is why Unicode’s own security report, UTR #36, treats confusable characters as a standing risk, and why some registries restrict mixed-script labels. Coverage is patchy, though, and a single swapped character is often enough.
Defense has to work on the raw name, not the rendered one. notolens decodes internationalized candidates before matching, so a Cyrillic swap surfaces in your inbox the same way a plain typo would.
How typosquatters make money
Measurement research finds that most typosquatted domains carry pay-per-click advertising: the mistyped visitor sees a page of ads, often including ads for the real brand, and the squatter collects a fraction of a cent per visit at scale. The remaining minority is where the damage concentrates:
- Phishing and credential theft. A pixel-perfect copy of a sign-in page that posts credentials elsewhere. Combosquatted names like
brand-login.comexist largely for this purpose. - Malware delivery. Drive-by downloads and fake software updates, a technique tracked in MITRE ATT&CK as T1583.001.
- Traffic and affiliate redirect. Sending the visitor to a competitor or an affiliate checkout to capture the intended purchase.
- Resale. Offering to sell the domain back to the brand owner, which US law treats as a textbook indicator of bad faith.
- Mail interception. A lookalike domain with MX records can receive misaddressed email, a quiet channel for invoice fraud and business email compromise.
A parked page today is not proof the domain is harmless. The same measurement work found squatters routinely change monetization strategy over time, and a domain that lapses can be re-registered by a different operator later.
Why small brands are targets too
The largest measurement study of the .com zone (Szurdi et al., USENIX Security 2014) estimated that roughly 20% of all .com registrations were typo domains, and found that only 6.8% of them targeted the 10,000 most popular sites. The remaining 93% targeted the long tail: mid-size and small brands that are less likely to monitor for abuse.
The raw material is enormous. Verisign reported 386.9 million domain registrations across all TLDs at the end of 2025, with 10.7 million new .com and .net names registered in Q4 2025 alone. Nobody can check that volume by hand; even the biggest brands only see the variants that surface through complaints or monitoring.
The consequences show up in crime statistics. The FBI’s IC3 received 193,407 phishing and spoofing complaints in 2024, making it the single most reported crime type, and total reported losses reached $16.6 billion. WIPO trademark holders filed a record 6,282 domain dispute cases in 2025, bringing the total since 1999 to over 80,000 cases covering more than 143,000 domain names.
Typosquatting vs. cybersquatting
The terms overlap but are not interchangeable. Cybersquatting covers the general practice of registering domains that target someone else’s trademark for profit, for example registering a competitor’s product name hoping to resell it. Typosquatting is the narrower tactic built on typing errors and visual similarity. Both fall under the same legal frameworks: the UDRP treats confusingly similar registrations as abusive, and the ACPA covers any domain “identical or confusingly similar” to a protected mark, typo variants included.
Legal remedies and enforcement options
Three mechanisms cover most situations, from cheapest to most formal:
- Registrar and hosting abuse reports. When a lookalike is actively phishing or distributing malware, providers suspend it under their acceptable use policies. Our guides cover reporting domain abuse to a registrar and reporting hosting abuse step by step.
- UDRP complaint. ICANN’s administrative process lets a trademark owner recover a domain by proving confusing similarity, no legitimate interest, and bad-faith registration and use. Remedies are transfer or cancellation, and decisions typically arrive within 45 to 60 days. See how to file a UDRP domain dispute.
- ACPA litigation. In US federal court, the Anticybersquatting Consumer Protection Act allows statutory damages of $1,000 to $100,000 per domain, plus forfeiture or transfer. Its in rem provision lets a court act on the domain itself when the registrant cannot be identified or reached, which matters because squatters routinely hide behind privacy services.
None of these require proving the squatter’s intent at detection time. What they all reward is documentation: dated registration records, screenshots, DNS evidence, and a clear timeline of when the domain appeared and what it showed.
How to catch typosquats early
Typosquatting is a volume game on both sides. The attacker registers hundreds of candidates cheaply; the defender’s job is to see each new one the day it appears, not after a customer reports a scam.
A one-off search shows what exists today. Domain monitoring watches the daily stream of new registrations and flags variants the day they are registered, while there is still time to act before the domain is weaponized. Watching the registration stream also catches the dormant pattern: a domain parked harmlessly for months that suddenly starts serving a phishing kit.
For a point-in-time view, the domain watch report shows every lookalike registration of your brand from the last 30 days, and the lookalike domain generator enumerates the variant space an attacker would choose from.
Sources
- Center for Internet Security: typosquatting techniques and taxonomy
- MITRE ATT&CK T1583.001: Acquire Infrastructure, Domains
- WIPO Arbitration and Mediation Center: 2025 caseload highlights
- 15 U.S.C. § 1125: cyberpiracy prevention (ACPA)
- FBI IC3: 2024 Internet Crime Report
- Szurdi et al., The Long "Taile" of Typosquatting Domain Names (USENIX Security 2014)
- Spaulding et al., The Landscape of Domain Name Typosquatting (survey)
- Verisign: Q4 2025 results and domain name base (SEC filing)
- Unicode Technical Report #36: security considerations for confusable characters
Frequently asked questions
Typosquatting is not automatically illegal, but it becomes actionable when a domain is registered or used in bad faith to profit from someone else’s trademark. In the US, the Anticybersquatting Consumer Protection Act creates civil liability for bad-faith registrations, with statutory damages of $1,000 to $100,000 per domain. Internationally, the UDRP lets trademark owners recover abusive domains through an administrative process without going to court.
Cybersquatting is the umbrella term for registering domain names that target someone else’s trademark in bad faith. Typosquatting is a subset of cybersquatting that specifically exploits typing errors and visually similar characters.
No. Academic measurement research found that only 6.8% of typo domains target the 10,000 most popular .com sites. The long tail of smaller brands makes up the overwhelming majority of typosquatting targets, precisely because those brands are less likely to be watching.
First record the facts: registration date, registrar, DNS and mail setup, and what the site shows. If it is being used for phishing or impersonation, report it to the sponsoring registrar and hosting provider. To recover the name itself, a UDRP complaint is the standard route for trademark holders. For anything beyond procedural steps, consult qualified counsel.
A successful UDRP complaint results in transfer or cancellation of the domain. To succeed, you must show the domain is identical or confusingly similar to your mark, that the registrant has no legitimate interest in it, and that it was registered and used in bad faith. Decisions typically arrive within 45 to 60 days.
Related tools and resources
Lookalike Domain Generator
Enumerate every lookalike variant of your domain: typos, homoglyphs, vowel swaps, and more.
Domain Monitoring
Daily monitoring for lookalike registrations and typosquatting, with every match checked and explained.
How to Report Domain Abuse to a Registrar
Collect the required evidence and submit a suspension report that registrars act on.
Catch typosquats the day they register.
notolens checks every new registration against your brand, scores and explains the risk, and keeps the records you need for a report or dispute. Clear monthly pricing, no sales calls.
Start monitoring in 3 minutes