Combosquatting: the brand-plus-keyword disguise
Updated October 3, 2026
Combosquatting domains keep your brand name intact and add a plausible word: notolens-login.com, notolens-support.net. Nothing is misspelled, which is why they slip past both readers and typo-based detection.
- Coined by
- Kintis et al., ACM CCS 2017
- Study scale
- 468B DNS records over ~6 years
- Lifespan
- ~60% of abusive ones live 1,000+ days
A combosquat is built by addition, not corruption: the complete brand name plus a plausible keyword. paypal-members.com, youtube-live.com, betterfacebook.com: examples cataloged by Kintis and colleagues, who coined the term in the first large-scale study of the technique at ACM CCS 2017.
What the research found
Analyzing more than 468 billion DNS records across nearly six years, the study established three things that still describe the technique:
- Scale and growth. Combosquatting is widespread and its activity increased year over year through the study period.
- Longevity. Almost 60% of abusive combosquatting domains stayed registered for more than 1,000 days. These names persist because they look legitimate and rarely trigger complaints.
- Abuse range. Phishing, social engineering, affiliate fraud, trademark abuse, and infrastructure for advanced persistent threats all appeared in the data.
The persuasion trick is subtle. Users are trained to check a URL for spelling errors; a combosquat has none. yourbank-security.com reads as a department, not a mistake; the appended word explains the unfamiliar full name away.
Why generators cannot find them
Variant generators, including our own lookalike domain generator, enumerate corruptions of the label: dropped letters, swapped vowels, homoglyph characters, bit flips. A combosquat corrupts nothing. The brand appears verbatim, surrounded by a word the generator cannot predict, because the attacker chose it for persuasion value rather than typo proximity.
Detection therefore works the other direction: instead of generating what attackers might register, match the intact brand token inside whatever was registered. notolens’s keyword matching flags a candidate when its label contains the brand in full: notolens-login.com trips the same detector whether the suffix is login, verify, or something new. The domain watch report shows which combinations were registered against your brand in the last 30 days.
What to do when one appears
Combosquats that serve phishing pages, fake support flows, or copied content are straightforward abuse reports: the registrar and hosting provider each control a layer that can take the content or the name offline. Where the name itself matters, as with a persistent phishing brand or a domain you want recovered, the intact brand token inside the label makes confusing similarity easy to argue in a UDRP complaint.
Sources
Frequently asked questions
Typosquatting corrupts the brand name itself, a dropped letter or a swapped vowel, and relies on a mistyping or a skimmed glance. Combosquatting leaves the brand intact and appends an unrelated word. The name is spelled correctly; the deception is that brand-login.com feels like an official subdomain or service even though it is a separate registration owned by someone else.
Words that imply an official function: login, support, secure, verify, billing, help, app, mail, account. The keyword does persuasion work: it tells the victim why the unfamiliar full name should still be trusted.
Generators permute the characters of your brand: omissions, substitutions, homoglyphs. A combosquat keeps every character and adds a keyword, so it never appears in generated variant lists. Catching it requires matching on the intact brand token inside a longer label, which is a different detection pass entirely.
No. Combosquatting happens at the registrable-domain level: the attacker owns the whole label. A subdomain such as brand.evil-example.com lives under a domain the attacker already controls, so the registrable name is what an abuse report or UDRP complaint acts on. It is also what registration monitoring sees, since subdomains never appear in registration feeds.
Registering a brand-plus-keyword domain is actionable under the UDRP and the Anticybersquatting Consumer Protection Act when it was registered and used in bad faith, which phishing, counterfeit sales, or impersonating support pages readily establish. The keyword alone is not infringement, but confusion-driven use usually is.
Related tools and resources
Domain Watch Report
See every lookalike registration of your brand, combosquats included, from the last 30 days.
Typosquatting
The full range of lookalike registration techniques, scale data, and defenses.
How to Report Domain Abuse to a Registrar
Find the sponsoring registrar and submit an actionable abuse report.
Continuous brand monitoring
notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.