Typosquatting

TypoSquatting: Ways to Protect your Brand

About Author

Picture of Oren Todoros

Oren Todoros

Oren is a cybersecurity and digital risk intelligence expert at BrandShield, focused on protecting organizations from online fraud, brand impersonation, and phishing attacks. He writes about emerging threats across digital ecosystems and strategies for proactive brand protection at scale.

BrandShield combines advanced AI and expert enforcement to help brands detect and remove online threats fast. Stop infringement, safeguard your reputation, and build lasting trust; all in one platform. Book a demo to learn more.

Typosquatting is the practice of registering a domain that closely resembles a legitimate website, often by changing, adding, or removing a character. Attackers can use these lookalike domains to impersonate brands, divert traffic, support phishing, or deceive customers.

In 2026, typosquatting remains an important brand protection and cybersecurity issue because a fake domain can look convincing at a glance. A single changed letter may be enough to send a customer to a completely different website.

Key Takeaways

  • Typosquatting uses domains that closely resemble legitimate brand domains.
  • Common tactics include missing letters, added characters, swapped letters, and similar-looking characters.
  • Fake domains can support phishing, impersonation, counterfeit sales, and traffic diversion.
  • Defensive domain registration can reduce some risk, but brands cannot register every possible variation.
  • Continuous domain monitoring helps identify suspicious registrations earlier.
  • Trademark owners may have enforcement options through processes such as the UDRP when the required conditions apply.

What Is Typosquatting?

Typosquatting is a form of domain abuse in which someone registers a web address designed to resemble a legitimate domain and benefit from user mistakes or confusion.

For example, an attacker might add one letter, remove a character, or swap two letters in a well-known domain. The resulting address may look correct when someone scans it quickly.

Typosquatting is related to cybersquatting, but the terms are not identical.

ICANN describes cybersquatting as the bad-faith registration of another party’s trademark in a domain name. [VERIFY] Read ICANN’s explanation of cybersquatting.

Typosquatting focuses more specifically on confusing variations of legitimate domains. Therefore, attackers often rely on people overlooking small differences.

For a broader explanation of related tactics, see BrandShield’s guide to domain squatting and online impersonation.

How Does Typosquatting Work?

Typosquatting works by creating a domain close enough to a real address that users may not notice the difference before visiting it.

Attackers can create these variations in several ways.

Adding a Letter

An attacker can add an extra character to a brand domain.

For example, a domain with one repeated letter may look correct during a quick scan. This is especially relevant on mobile screens, where URLs can be harder to inspect.

Removing a Letter

Another common tactic is deleting one character from a legitimate domain.

Therefore, a user who makes a simple typing error may land on an attacker-controlled site.

Swapping Characters

Attackers may reverse two letters that commonly appear next to each other.

For example, a user typing quickly may make the same error naturally. The attacker registers that mistake in advance.

Using Similar-Looking Characters

Some domains use characters that visually resemble those in the legitimate address.

This can include characters from different alphabets or numbers that resemble letters. These attacks can be harder to spot because the domain may look almost identical on screen.

Adding Words to a Brand Domain

Not every deceptive domain depends on a spelling error.

For example, attackers may combine a brand with words such as:

  • login
  • support
  • account
  • secure
  • verify
  • shop
  • payment

These domains fall more broadly under lookalike domain or brand impersonation threats. However, organizations should monitor them alongside typosquatting because the customer risk can be similar.

Why Is Typosquatting Dangerous for Brands?

Typosquatting can damage brands because attackers can use lookalike domains to exploit the trust customers already place in a legitimate company.

The domain itself is often only the first step.

Once an attacker controls a convincing address, they can build a website around it. For example, they may copy logos, product images, login screens, or other parts of the genuine site.

That creates several potential risks.

Phishing

A typosquatting domain can host a fake login or payment page.

As a result, customers may enter passwords, account details, or other sensitive information while believing they are on the legitimate website.

BrandShield’s guide to preventing phishing scams explains how phishing campaigns use brand impersonation to build trust with victims.

Brand Impersonation

Attackers can copy the appearance of an official website and place it on a confusingly similar domain.

Therefore, even customers who check the page design may believe the site is genuine.

The fake site may then offer fraudulent customer support, fake promotions, account verification, or other deceptive services.

Counterfeit Sales

Lookalike domains can also host online stores selling counterfeit products.

For example, a fake store may copy product images and branding from the genuine company. Customers may believe they are purchasing directly from the brand.

Traffic Diversion

Some domains exist mainly to capture traffic intended for the legitimate business.

The operator may show advertisements, redirect visitors elsewhere, or promote competing products.

Therefore, the impact can include lost traffic as well as direct fraud.

Email Impersonation

A lookalike domain can also create convincing email addresses.

For example, an attacker may use an address that looks similar to a real employee or company account.

This means typosquatting is not only a website issue. It can also support broader impersonation and phishing campaigns.

What Is the Difference Between Typosquatting and Cybersquatting?

Typosquatting relies on confusing variations of a legitimate domain, while cybersquatting is the broader bad-faith registration of domains tied to another party’s trademark or identity.

ICANN describes cybersquatting as a form of misuse in which a party intentionally registers a domain that coincides with a commercial trademark or the name of a well-known person. [VERIFY]

Typosquatting is therefore one tactic that can sit within the wider domain-abuse problem.

For example:

  • Typosquatting: changing or omitting a letter from a brand’s domain.
  • Cybersquatting: registering a domain tied to another company’s trademark in bad faith.
  • Lookalike domains: using words, characters, or naming patterns that make a domain appear connected to a legitimate brand.
  • Domain impersonation: using a domain and website together to pretend to represent the legitimate organization.

The distinctions matter because the evidence and enforcement options can differ from case to case.

How Can Brands Detect Typosquatting?

Brands can detect typosquatting by continuously monitoring new and existing domains for spelling variations, lookalike characters, trademark use, and other signs of impersonation.

Manual searches can identify obvious cases. However, large brands may have hundreds or thousands of possible domain variations.

Therefore, effective monitoring should consider several signals.

Common Misspellings

Start with mistakes customers are likely to make when typing the legitimate domain.

These can include missing letters, doubled characters, reversed letters, and nearby keyboard keys.

Similar-Looking Characters

Monitoring should also look for characters that resemble those used in the legitimate domain.

This helps identify visual impersonation that simple text matching might miss.

Brand-Plus-Keyword Domains

Attackers may use the company’s trademark alongside words such as “login,” “support,” or “secure.”

Therefore, monitoring should extend beyond exact misspellings.

Website Content

A suspicious domain becomes more concerning when the website also copies official brand assets.

For example, teams can examine logos, product images, text, login forms, payment pages, and links.

Related Digital Threats

A typosquatting domain may connect to another fake website, paid advertisement, social account, or phishing campaign.

As a result, brands should investigate the wider network rather than reviewing the domain in isolation.

How Can You Prevent Typosquatting?

Brands can reduce typosquatting risk through defensive registrations, continuous monitoring, clear domain management, and fast investigation of suspicious registrations.

No company can register every possible variation. Therefore, prevention should focus on the domains most likely to create customer or business risk.

1. Register High-Risk Domain Variations

Consider registering the most obvious misspellings of your primary domain.

For example, prioritize errors customers commonly make and variations that could easily cause confusion.

Then redirect those defensive domains to your official website.

2. Secure Important Domain Extensions

Companies should consider which domain extensions matter to their markets and customers.

However, buying every available extension is rarely practical. Instead, prioritize extensions that create a realistic impersonation risk.

3. Monitor Domain Registrations Continuously

Defensive registration has limits.

Therefore, businesses also need monitoring that identifies suspicious domains when other parties register them.

BrandShield monitors websites and rogue domains as part of its digital risk protection capabilities, including phishing and brand impersonation threats.

4. Make Your Official Domains Clear

Customers should know where they can safely access your services.

For example, use consistent domain names across marketing, customer support, account communications, and social profiles.

This reduces uncertainty when customers encounter an unfamiliar website.

5. Prioritize Threats by Risk

Not every registered variation is actively harmful.

A parked domain may present less immediate risk than a cloned login page collecting credentials.

Therefore, teams should review the domain’s content, behavior, traffic signals, and connections before deciding what action to take.

What Should You Do If Someone Registers a Typosquatting Domain?

When you find a typosquatting domain, preserve evidence, assess how it uses your brand, investigate its behavior, and determine the appropriate enforcement route.

A practical response can follow these steps:

  1. Capture evidence. Save the domain, screenshots, website content, redirects, and other relevant information.
  2. Confirm the brand connection. Identify the trademark, logo, product, or company identity being used.
  3. Assess the threat. Determine whether the domain hosts phishing, counterfeit sales, impersonation, or other harmful content.
  4. Investigate connected assets. Look for related domains, social accounts, advertisements, or websites.
  5. Identify the right enforcement method. The route can depend on the registrar, hosting provider, trademark rights, domain extension, and type of abuse.
  6. Track the result. Continue monitoring because the same actor may register replacement domains.

Trademark owners may also have access to the Uniform Domain Name Dispute Resolution Policy, or UDRP, for certain abusive registrations.

ICANN explains that trademark-based domain disputes may be addressed through agreement, court action, or an approved dispute-resolution process. [VERIFY] Read ICANN’s UDRP guidance.

In addition, the World Intellectual Property Organization administers domain dispute cases and explains how trademark owners may use the UDRP and relevant country-code policies. [VERIFY] See WIPO’s domain-name dispute guidance.

How Does BrandShield Help Detect Typosquatting?

BrandShield helps organizations identify suspicious domains and websites that may be used for typosquatting, phishing, impersonation, and other forms of digital brand abuse.

BrandShield monitors websites and domains alongside other channels. This helps teams identify external threats that customers may encounter outside the company’s own network.

For example, a lookalike domain may host a cloned website. It may also connect to fake social profiles or paid ads that drive traffic toward the scam.

Cross-channel analysis helps expose those relationships.

For broader guidance on responding to trademark abuse, read BrandShield’s guide on how to report trademark violations online.

Typosquatting FAQ

What is typosquatting?

Typosquatting is the registration of a domain designed to resemble a legitimate web address by using likely spelling mistakes or similar characters. Attackers may use these domains for phishing, impersonation, counterfeit sales, advertising, or traffic diversion.

Is typosquatting the same as cybersquatting?

No. Typosquatting focuses on confusing variations of legitimate domains, while cybersquatting is a broader term for bad-faith domain registrations involving another party’s trademark or identity. However, the two practices can overlap.

Why is typosquatting dangerous?

Typosquatting can send customers to sites they mistakenly believe belong to a trusted company. Those sites may collect credentials, sell fake products, impersonate support teams, or redirect visitors elsewhere.

How can companies find typosquatting domains?

Companies can monitor domain registrations for misspellings, added or removed characters, similar-looking letters, and brand-related keywords. They should also review the content and behavior of suspicious sites to determine their level of risk.

Can a company take down a typosquatting domain?

Potential enforcement options depend on the facts of the case, trademark rights, domain extension, and nature of the registration. For applicable trademark disputes, processes such as the UDRP may provide a route to recover or cancel an abusive domain. [VERIFY]

Typosquatting Requires More Than Defensive Registration

Typosquatting remains relevant in 2026 because attackers only need a small amount of confusion to exploit a trusted brand.

Registering obvious misspellings can help. However, defensive domains alone cannot cover every possible variation.

Therefore, brands need continuous visibility into new domains, lookalike websites, and related impersonation activity.

The most effective approach combines defensive registration, monitoring, risk assessment, and enforcement. It also looks beyond one domain to identify the broader infrastructure behind an attack.

To see how BrandShield can help identify typosquatting, suspicious domains, phishing websites, and other external brand threats, talk to the BrandShield team.

Get a Free Brand Assestment

See how BrandShield uncovers counterfeit networks, detects brand abuse across marketplaces, social and AI platforms, and removes threats quickly and at scale.

Recommended for you