# What is typosquatting?

Typosquatting refers to the deliberate registration of domains that look almost identical to well-known web addresses and contain only minimal typing errors. The goal is to catch users who mistype a web address and redirect them to fake or misleading websites.

## How does typosquatting work?

Typosquatting relies on small changes to a domain name. A letter may be omitted, swapped, or replaced with a visually similar character. Homoglyph attacks are especially difficult to spot. In these cases, attackers might use the digit “0” instead of the letter “O” or Unicode characters from other alphabets. These variations are barely noticeable to the human eye.

Classic examples often involved misspelled names of major search engines or online stores. Today, typosquatting increasingly targets SaaS services, cloud platforms, AI tools, and payment providers. Fake login pages that imitate ChatGPT, Microsoft 365, or well-known crypto platforms show how professional these attacks have become. The goal is to redirect accidental traffic and profit from it. In more serious cases, attackers use highly convincing login pages to steal credentials or payment information. For companies, every typosquatting incident can mean a potential loss of customers.

Note Typosquatting is often confused with [cybersquatting](https://www.ionos.com/digitalguide/domains/domain-administration/domain-grabbing-cybersquatting/), but the intent is different. Rather than blocking or reselling a brand domain, typosquatting aims to capture traffic with domain names that differ only slightly from the original.

## Common types of typosquatting

Criminals use several forms of typosquatting to mislead users. These are the most common types:

- **Typos:** Transposed letters, doubled characters, or missing characters are among the most common variants. Attackers create domains that differ only slightly from a well-known address. Many major brands now register these versions themselves and use a [redirect](https://www.ionos.com/digitalguide/websites/web-development/301-redirects/) to send users to the main domain before the addresses can be misused.
- **Spelling mistakes:** Not every incorrect domain comes from typing too quickly. Permanently misspelled brand or product names are also deliberately registered as a [domain](https://www.ionos.com/digitalguide/domains/domain-tips/what-is-a-domain/). These variants can generate significant traffic, especially for popular brands.
- **Alternative spellings:** Different spellings of common words can also create opportunities for typosquatting. For example, a business using `www.travelerdeals.com` may also need to consider whether users might enter `www.travellerdeals.com`.
- **Hyphen domains:** Domains with and without hyphens are especially vulnerable. Adding or removing a hyphen creates a separate address. Typosquatters also combine well-known brands with additions such as “shop,” “online,” or “service” to suggest an official connection.
- **Incorrect domain endings:** The large number of [new top-level domains](https://www.ionos.com/digitalguide/domains/domain-extensions/the-new-tlds-top-level-domains/) has increased the risk further. A brand registered under .com, for example, can also be registered under .shop, .online, or .web. The .co ending is especially popular because it closely resembles .com. If you only register one TLD, you risk leaving alternative endings open to misleading or fraudulent use.

<table>
  <thead>
    <tr>
      <th>Variant</th>
      <th>Description</th>
      <th>Example</th>
      <th>Main risk</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Classic typo</td>
      <td>Transposed, doubled, or missing letters</td>
      <td>`amazom.com` instead of `amazon.com`</td>
      <td>Traffic interception, redirection to ad pages</td>
    </tr>
    <tr>
      <td>Spelling mistake</td>
      <td>Permanently misspelled brands</td>
      <td>`linkdin.com` instead of `linkedin.com`</td>
      <td>Deception, data theft</td>
    </tr>
    <tr>
      <td>Alternative spelling</td>
      <td>Different spellings of the same term</td>
      <td>`colorprint.com` vs. `colourprint.com`</td>
      <td>Customer loss, brand dilution</td>
    </tr>
    <tr>
      <td>Hyphen variant</td>
      <td>Adding or removing hyphens</td>
      <td>`online-bank-login.com`</td>
      <td>Misleading login pages</td>
    </tr>
    <tr>
      <td>Brand addition</td>
      <td>Adding trust-building terms</td>
      <td>`delivery-tracking.com`</td>
      <td>[Phishing](https://www.ionos.com/digitalguide/server/security/what-is-phishing/), theft of personal data</td>
    </tr>
    <tr>
      <td>Different TLD</td>
      <td>Same name with a different ending</td>
      <td>`company-support.co` instead of `company-support.com`</td>
      <td>Login abuse</td>
    </tr>
    <tr>
      <td>Homoglyph attack</td>
      <td>Replacement with visually similar characters</td>
      <td>`rnicrosoft.com` (rn instead of m)</td>
      <td>Hard-to-detect phishing</td>
    </tr>
    <tr>
      <td>IDN/Unicode abuse</td>
      <td>Use of foreign alphabet characters with an identical appearance</td>
      <td>`аррle.com` (Cyrillic characters)</td>
      <td>Highly professional scam sites</td>
    </tr>
  </tbody>
</table>

## Typosquatting in SaaS and AI environments

Typosquatting has become much more professional in recent years. Instead of relying on simple ad redirects, attackers now focus on high-value accounts and **sensitive login details**. Cloud services, project management tools, payment platforms, and AI applications with paid subscriptions are especially attractive targets.

Attackers register domains that look almost identical to official login pages. They combine common typos with trust-building terms such as “secure,” “verify,” or “account” and often use valid [TLS certificates](https://www.ionos.com/digitalguide/server/security/tls-transport-layer-security/). This can make the page look legitimate at first glance.

**Typical scenarios** include:

- Fake login portals for project management or collaboration tools
- Fake invoice pages from parcel delivery services
- Imitated payment or wallet portals
- Imitated AI platforms with supposed upgrade notices
- Domains with minimal character changes, such as 1 instead of l or 0 instead of O

AI-supported website generation makes it easier to create convincing copies of real provider websites in a very short time. As a result, typosquatting is no longer just a way to capture accidental traffic. It has become a key part of modern phishing strategies and creates concrete risks for companies:

- Loss of potential customers
- Damage to brand image and reputation
- Increased support and security costs
- Possible data exposure due to compromised login credentials

## What is the legal situation with typosquatting in the US?

Typosquatting is not automatically illegal in the United States. In many cases, however, registering and using a typo domain can violate trademark law, unfair competition rules, or anti-cybersquatting laws. The key question is usually whether the domain creates confusion, infringes protected trademark rights, or was registered in bad faith.

### Trademark law

[Trademark law](https://www.ionos.com/digitalguide/websites/digital-law/the-basics-of-trademark-law/) is often the main legal basis. If a domain is confusingly similar to a protected trademark and is used in a way that could mislead users, this may constitute trademark infringement. The decisive factor is whether users could reasonably assume that the typo domain is connected to the actual trademark owner.

Possible steps may include:

- Demanding that the domain holder stop using the domain
- Seeking transfer or cancelation of the domain
- Claiming damages in certain cases

Cases are especially clear when the typo domain is used for identical or closely related goods or services.

### Anti-cybersquatting law

The US also has a specific legal basis for domain abuse, entitled the [Anticybersquatting Consumer Protection Act (ACPA)](https://www.govinfo.gov/content/pkg/CRPT-106srpt140/html/CRPT-106srpt140.htm "Anticybersquatting Consumer Protection Act (ACPA)"). It applies when someone registers, uses, or traffics in a domain name that is identical or confusingly similar to a distinctive or famous trademark, with a bad-faith intent to profit.

Under the ACPA, trademark owners may be able to seek:

- Transfer or cancelation of the domain
- Injunctive relief
- Monetary damages in certain cases

### Unfair competition

Typosquatting may also fall under unfair competition principles, especially when a domain is used to divert customers, imitate a business, or create a false impression of affiliation. This is particularly relevant when users are redirected to competing offers or fake login pages.

### Criminal relevance

If a typo domain is used for [phishing](https://www.ionos.com/digitalguide/server/security/what-is-phishing/), identity theft, payment fraud, or credential theft, the issue can go beyond a civil trademark dispute. Depending on the case, criminal laws related to fraud, computer misuse, or identity theft may also apply.

### International dispute resolution for domains

Because domains can be registered globally, court proceedings are not always the fastest option. For many top-level domains, trademark owners can use the [Uniform Domain-Name Dispute-Resolution Policy (UDRP)](https://www.ionos.com/digitalguide/domains/domain-administration/udrp-explanation-and-procedure/). This out-of-court procedure is administered by approved providers, including the [World Intellectual Property Organization (WIPO)](https://www.wipo.int/portal/en/index.html "Official World Intellectual Property Organization website").

For a successful UDRP complaint, the trademark owner generally has to show that:

- the domain is identical or confusingly similar to a protected trademark,
- the domain holder has no rights or legitimate interests in the domain, and
- the domain was registered and is being used in bad faith.

A UDRP proceeding can lead to the transfer or cancelation of the domain without a national court case.

## Typosquatting from a business and private user perspective

Typosquatting can affect both businesses and private individuals, but the risks are not the same.

<table>
  <thead>
    <tr>
      <th>Perspective</th>
      <th>Risk</th>
      <th>Typical consequences</th>
      <th>Protection approach</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Businesses</td>
      <td>Brand abuse, traffic loss, phishing under their own name</td>
      <td>Loss of revenue, reputational damage, higher support and security costs</td>
      <td>Domain strategy, monitoring, trademark registration, technical safeguards</td>
    </tr>
    <tr>
      <td>Private individuals</td>
      <td>Entering login credentials on fake sites</td>
      <td>Account takeover, identity theft, financial loss</td>
      <td>Checking URLs, password manager, two-factor authentication</td>
    </tr>
  </tbody>
</table>

Businesses usually need to respond with a combination of strategic, technical, and legal measures. For private users, the focus is more on everyday caution and basic security practices. In both cases, typosquatting is not just a theoretical risk, but a practical security issue in daily digital life.

## How to protect yourself against typosquatting

You cannot prevent typosquatting completely. However, you can reduce the risk significantly by combining a clear domain strategy with technical safeguards and internal processes.

- **Register common spelling variants early:** Secure common typos, alternative spellings, relevant hyphenated versions, and important domain extensions for your brand. Frequently used typo domains can redirect to your main domain to prevent misuse.
- **Reserve important domain extensions:** In addition to your primary domain, register key extensions such as .com, .net, .org, or industry-specific TLDs like .shop, .store, or .online. This reduces the risk of third parties using your brand under alternative extensions.
- **Use domain monitoring:** Use monitoring services that scan newly registered domains for names similar to your brand. Early alerts help you respond before harmful content spreads.
- **Protect your brand through trademark registration:** Register your trademark nationally or internationally. A registered trademark makes it much easier to enforce your rights, for example through a UDRP proceeding or legal action.
- **Strengthen DNS and email security:** Add technical safeguards that make your domain infrastructure harder to abuse. These include [DNSSEC](https://www.ionos.com/digitalguide/server/know-how/dnssec-internet-standards-for-authenticated-name-resolution/) to secure name resolution, as well as [SPF](https://www.ionos.com/digitalguide/e-mail/e-mail-security/what-is-an-spf-record/), [DKIM](https://www.ionos.com/digitalguide/e-mail/e-mail-security/dkim-domainkeys/), and [DMARC](https://www.ionos.com/digitalguide/e-mail/e-mail-security/dmarc-domain-based-message-authentication-reporting-and-conformance/) to help prevent [email spoofing](https://www.ionos.com/digitalguide/server/security/what-is-spoofing/).
- **Raise awareness among employees and customers:** Train employees to recognize suspicious links and login pages. Also make it clear to customers which official domains and communication channels you use.
- **Act quickly and consider legal action:** If you discover an abusive domain, document its content and assess potential trademark or unfair competition claims. The faster you respond, the lower the risk of reputational damage, data misuse, or customer loss.

## How to recognize a typosquatting site

Typosquatting sites are often professionally designed and technically convincing. Even so, there are common warning signs that can point to a manipulated or fake domain:

- **Check the URL carefully:** Look at the web address character by character. Pay attention to swapped letters, extra characters, missing letters, or lookalike combinations such as “rn” instead of “m” or “0” instead of “O”.
- **Watch for unusual domain extensions:** Be cautious if a well-known brand suddenly appears under an unfamiliar extension such as .co, .online, or .shop.
- **Look for suspicious additions in the domain:** Terms such as “secure,” “verify,” “login,” or “support” combined with a brand name are common in phishing domains.
- **Be wary of login pages without context:** If you land directly on a login page without actively requesting it, check the URL especially carefully.
- **Pay attention to unusual redirects:** Multiple automatic redirects or a URL that changes after the page loads can indicate manipulation.
- **Do not rely on the certificate alone:** A valid TLS certificate (https) only shows that the connection is encrypted. It does not prove that the site is legitimate.
- **Check for spelling or layout errors:** Many phishing sites now look professional, but faulty text or inconsistent design can still be a warning sign.

Technical tools such as [password managers](https://www.ionos.com/digitalguide/server/security/password-managers-an-overview-of-todays-best-tools/) add another layer of protection. They usually auto-fill login details only on the exact domain you have saved, which can help alert you to typo domains created through typosquatting.


This is a markdown version of: [https://www.ionos.com/digitalguide/domains/domain-tips/how-to-protect-your-domain-from-typosquatting/](https://www.ionos.com/digitalguide/domains/domain-tips/how-to-protect-your-domain-from-typosquatting/) for AI/LLM consumption.