Skip to content

Combosquatting: the brand-plus-keyword disguise

Updated October 3, 2026

Combosquatting domains keep your brand name intact and add a plausible word: notolens-login.com, notolens-support.net. Nothing is misspelled, which is why they slip past both readers and typo-based detection.

Coined by
Kintis et al., ACM CCS 2017
Study scale
468B DNS records over ~6 years
Lifespan
~60% of abusive ones live 1,000+ days

A combosquat is built by addition, not corruption: the complete brand name plus a plausible keyword. paypal-members.com, youtube-live.com, betterfacebook.com: examples cataloged by Kintis and colleagues, who coined the term in the first large-scale study of the technique at ACM CCS 2017.

What the research found

Analyzing more than 468 billion DNS records across nearly six years, the study established three things that still describe the technique:

  • Scale and growth. Combosquatting is widespread and its activity increased year over year through the study period.
  • Longevity. Almost 60% of abusive combosquatting domains stayed registered for more than 1,000 days. These names persist because they look legitimate and rarely trigger complaints.
  • Abuse range. Phishing, social engineering, affiliate fraud, trademark abuse, and infrastructure for advanced persistent threats all appeared in the data.

The persuasion trick is subtle. Users are trained to check a URL for spelling errors; a combosquat has none. yourbank-security.com reads as a department, not a mistake; the appended word explains the unfamiliar full name away.

Why generators cannot find them

Variant generators, including our own lookalike domain generator, enumerate corruptions of the label: dropped letters, swapped vowels, homoglyph characters, bit flips. A combosquat corrupts nothing. The brand appears verbatim, surrounded by a word the generator cannot predict, because the attacker chose it for persuasion value rather than typo proximity.

Detection therefore works the other direction: instead of generating what attackers might register, match the intact brand token inside whatever was registered. notolens’s keyword matching flags a candidate when its label contains the brand in full: notolens-login.com trips the same detector whether the suffix is login, verify, or something new. The domain watch report shows which combinations were registered against your brand in the last 30 days.

What to do when one appears

Combosquats that serve phishing pages, fake support flows, or copied content are straightforward abuse reports: the registrar and hosting provider each control a layer that can take the content or the name offline. Where the name itself matters, as with a persistent phishing brand or a domain you want recovered, the intact brand token inside the label makes confusing similarity easy to argue in a UDRP complaint.

Sources

Frequently asked questions

Related tools and resources

Continuous brand monitoring

notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.