Ty­posquat­ting refers to the de­lib­er­ate reg­is­tra­tion of domains that look almost identical to well-known web addresses and contain only minimal typing errors. The goal is to catch users who mistype a web address and redirect them to fake or mis­lead­ing websites.

How does ty­posquat­ting work?

Ty­posquat­ting relies on small changes to a domain name. A letter may be omitted, swapped, or replaced with a visually similar character. Homoglyph attacks are es­pe­cial­ly difficult to spot. In these cases, attackers might use the digit “0” instead of the letter “O” or Unicode char­ac­ters from other alphabets. These vari­a­tions are barely no­tice­able to the human eye.

Classic examples often involved mis­spelled names of major search engines or online stores. Today, ty­posquat­ting in­creas­ing­ly targets SaaS services, cloud platforms, AI tools, and payment providers. Fake login pages that imitate ChatGPT, Microsoft 365, or well-known crypto platforms show how pro­fes­sion­al these attacks have become. The goal is to redirect ac­ci­den­tal traffic and profit from it. In more serious cases, attackers use highly con­vinc­ing login pages to steal cre­den­tials or payment in­for­ma­tion. For companies, every ty­posquat­ting incident can mean a potential loss of customers.

Note

Ty­posquat­ting is often confused with cy­ber­squat­ting, but the intent is different. Rather than blocking or reselling a brand domain, ty­posquat­ting aims to capture traffic with domain names that differ only slightly from the original.

Common types of ty­posquat­ting

Criminals use several forms of ty­posquat­ting to mislead users. These are the most common types:

  • Typos: Trans­posed letters, doubled char­ac­ters, or missing char­ac­ters are among the most common variants. Attackers create domains that differ only slightly from a well-known address. Many major brands now register these versions them­selves and use a redirect to send users to the main domain before the addresses can be misused.
  • Spelling mistakes: Not every incorrect domain comes from typing too quickly. Per­ma­nent­ly mis­spelled brand or product names are also de­lib­er­ate­ly reg­is­tered as a domain. These variants can generate sig­nif­i­cant traffic, es­pe­cial­ly for popular brands.
  • Al­ter­na­tive spellings: Different spellings of common words can also create op­por­tu­ni­ties for ty­posquat­ting. For example, a business using www.travelerdeals.com may also need to consider whether users might enter www.travellerdeals.com.
  • Hyphen domains: Domains with and without hyphens are es­pe­cial­ly vul­ner­a­ble. Adding or removing a hyphen creates a separate address. Ty­posquat­ters also combine well-known brands with additions such as “shop,” “online,” or “service” to suggest an official con­nec­tion.
  • Incorrect domain endings: The large number of new top-level domains has increased the risk further. A brand reg­is­tered under .com, for example, can also be reg­is­tered under .shop, .online, or .web. The .co ending is es­pe­cial­ly popular because it closely resembles .com. If you only register one TLD, you risk leaving al­ter­na­tive endings open to mis­lead­ing or fraud­u­lent use.
Variant De­scrip­tion Example Main risk
Classic typo Trans­posed, doubled, or missing letters amazom.com instead of amazon.com Traffic in­ter­cep­tion, redi­rec­tion to ad pages
Spelling mistake Per­ma­nent­ly mis­spelled brands linkdin.com instead of linkedin.com Deception, data theft
Al­ter­na­tive spelling Different spellings of the same term colorprint.com vs. colourprint.com Customer loss, brand dilution
Hyphen variant Adding or removing hyphens online-bank-login.com Mis­lead­ing login pages
Brand addition Adding trust-building terms delivery-tracking.com Phishing, theft of personal data
Different TLD Same name with a different ending company-support.co instead of company-support.com Login abuse
Homoglyph attack Re­place­ment with visually similar char­ac­ters rnicrosoft.com (rn instead of m) Hard-to-detect phishing
IDN/Unicode abuse Use of foreign alphabet char­ac­ters with an identical ap­pear­ance аррle.com (Cyrillic char­ac­ters) Highly pro­fes­sion­al scam sites

Ty­posquat­ting in SaaS and AI en­vi­ron­ments

Ty­posquat­ting has become much more pro­fes­sion­al in recent years. Instead of relying on simple ad redirects, attackers now focus on high-value accounts and sensitive login details. Cloud services, project man­age­ment tools, payment platforms, and AI ap­pli­ca­tions with paid sub­scrip­tions are es­pe­cial­ly at­trac­tive targets.

Attackers register domains that look almost identical to official login pages. They combine common typos with trust-building terms such as “secure,” “verify,” or “account” and often use valid TLS cer­tifi­cates. This can make the page look le­git­i­mate at first glance.

Typical scenarios include:

  • Fake login portals for project man­age­ment or col­lab­o­ra­tion tools
  • Fake invoice pages from parcel delivery services
  • Imitated payment or wallet portals
  • Imitated AI platforms with supposed upgrade notices
  • Domains with minimal character changes, such as 1 instead of l or 0 instead of O

AI-supported website gen­er­a­tion makes it easier to create con­vinc­ing copies of real provider websites in a very short time. As a result, ty­posquat­ting is no longer just a way to capture ac­ci­den­tal traffic. It has become a key part of modern phishing strate­gies and creates concrete risks for companies:

  • Loss of potential customers
  • Damage to brand image and rep­u­ta­tion
  • Increased support and security costs
  • Possible data exposure due to com­pro­mised login cre­den­tials

Ty­posquat­ting is not au­to­mat­i­cal­ly illegal in the United States. In many cases, however, reg­is­ter­ing and using a typo domain can violate trademark law, unfair com­pe­ti­tion rules, or anti-cy­ber­squat­ting laws. The key question is usually whether the domain creates confusion, infringes protected trademark rights, or was reg­is­tered in bad faith.

Trademark law

Trademark law is often the main legal basis. If a domain is con­fus­ing­ly similar to a protected trademark and is used in a way that could mislead users, this may con­sti­tute trademark in­fringe­ment. The decisive factor is whether users could rea­son­ably assume that the typo domain is connected to the actual trademark owner.

Possible steps may include:

  • Demanding that the domain holder stop using the domain
  • Seeking transfer or can­ce­la­tion of the domain
  • Claiming damages in certain cases

Cases are es­pe­cial­ly clear when the typo domain is used for identical or closely related goods or services.

Anti-cy­ber­squat­ting law

The US also has a specific legal basis for domain abuse, entitled the An­ti­cy­ber­squat­ting Consumer Pro­tec­tion Act (ACPA). It applies when someone registers, uses, or traffics in a domain name that is identical or con­fus­ing­ly similar to a dis­tinc­tive or famous trademark, with a bad-faith intent to profit.

Under the ACPA, trademark owners may be able to seek:

  • Transfer or can­ce­la­tion of the domain
  • In­junc­tive relief
  • Monetary damages in certain cases

Unfair com­pe­ti­tion

Ty­posquat­ting may also fall under unfair com­pe­ti­tion prin­ci­ples, es­pe­cial­ly when a domain is used to divert customers, imitate a business, or create a false im­pres­sion of af­fil­i­a­tion. This is par­tic­u­lar­ly relevant when users are redi­rect­ed to competing offers or fake login pages.

Criminal relevance

If a typo domain is used for phishing, identity theft, payment fraud, or cre­den­tial theft, the issue can go beyond a civil trademark dispute. Depending on the case, criminal laws related to fraud, computer misuse, or identity theft may also apply.

In­ter­na­tion­al dispute res­o­lu­tion for domains

Because domains can be reg­is­tered globally, court pro­ceed­ings are not always the fastest option. For many top-level domains, trademark owners can use the Uniform Domain-Name Dispute-Res­o­lu­tion Policy (UDRP). This out-of-court procedure is ad­min­is­tered by approved providers, including the World In­tel­lec­tu­al Property Or­ga­ni­za­tion (WIPO).

For a suc­cess­ful UDRP complaint, the trademark owner generally has to show that:

  • the domain is identical or con­fus­ing­ly similar to a protected trademark,
  • the domain holder has no rights or le­git­i­mate interests in the domain, and
  • the domain was reg­is­tered and is being used in bad faith.

A UDRP pro­ceed­ing can lead to the transfer or can­ce­la­tion of the domain without a national court case.

Ty­posquat­ting from a business and private user per­spec­tive

Ty­posquat­ting can affect both busi­ness­es and private in­di­vid­u­als, but the risks are not the same.

Per­spec­tive Risk Typical con­se­quences Pro­tec­tion approach
Busi­ness­es Brand abuse, traffic loss, phishing under their own name Loss of revenue, rep­u­ta­tion­al damage, higher support and security costs Domain strategy, mon­i­tor­ing, trademark reg­is­tra­tion, technical safe­guards
Private in­di­vid­u­als Entering login cre­den­tials on fake sites Account takeover, identity theft, financial loss Checking URLs, password manager, two-factor au­then­ti­ca­tion

Busi­ness­es usually need to respond with a com­bi­na­tion of strategic, technical, and legal measures. For private users, the focus is more on everyday caution and basic security practices. In both cases, ty­posquat­ting is not just a the­o­ret­i­cal risk, but a practical security issue in daily digital life.

How to protect yourself against ty­posquat­ting

You cannot prevent ty­posquat­ting com­plete­ly. However, you can reduce the risk sig­nif­i­cant­ly by combining a clear domain strategy with technical safe­guards and internal processes.

  • Register common spelling variants early: Secure common typos, al­ter­na­tive spellings, relevant hy­phen­at­ed versions, and important domain ex­ten­sions for your brand. Fre­quent­ly used typo domains can redirect to your main domain to prevent misuse.
  • Reserve important domain ex­ten­sions: In addition to your primary domain, register key ex­ten­sions such as .com, .net, .org, or industry-specific TLDs like .shop, .store, or .online. This reduces the risk of third parties using your brand under al­ter­na­tive ex­ten­sions.
  • Use domain mon­i­tor­ing: Use mon­i­tor­ing services that scan newly reg­is­tered domains for names similar to your brand. Early alerts help you respond before harmful content spreads.
  • Protect your brand through trademark reg­is­tra­tion: Register your trademark na­tion­al­ly or in­ter­na­tion­al­ly. A reg­is­tered trademark makes it much easier to enforce your rights, for example through a UDRP pro­ceed­ing or legal action.
  • Strength­en DNS and email security: Add technical safe­guards that make your domain in­fra­struc­ture harder to abuse. These include DNSSEC to secure name res­o­lu­tion, as well as SPF, DKIM, and DMARC to help prevent email spoofing.
  • Raise awareness among employees and customers: Train employees to recognize sus­pi­cious links and login pages. Also make it clear to customers which official domains and com­mu­ni­ca­tion channels you use.
  • Act quickly and consider legal action: If you discover an abusive domain, document its content and assess potential trademark or unfair com­pe­ti­tion claims. The faster you respond, the lower the risk of rep­u­ta­tion­al damage, data misuse, or customer loss.

How to recognize a ty­posquat­ting site

Ty­posquat­ting sites are often pro­fes­sion­al­ly designed and tech­ni­cal­ly con­vinc­ing. Even so, there are common warning signs that can point to a ma­nip­u­lat­ed or fake domain:

  • Check the URL carefully: Look at the web address character by character. Pay attention to swapped letters, extra char­ac­ters, missing letters, or lookalike com­bi­na­tions such as “rn” instead of “m” or “0” instead of “O”.
  • Watch for unusual domain ex­ten­sions: Be cautious if a well-known brand suddenly appears under an un­fa­mil­iar extension such as .co, .online, or .shop.
  • Look for sus­pi­cious additions in the domain: Terms such as “secure,” “verify,” “login,” or “support” combined with a brand name are common in phishing domains.
  • Be wary of login pages without context: If you land directly on a login page without actively re­quest­ing it, check the URL es­pe­cial­ly carefully.
  • Pay attention to unusual redirects: Multiple automatic redirects or a URL that changes after the page loads can indicate ma­nip­u­la­tion.
  • Do not rely on the cer­tifi­cate alone: A valid TLS cer­tifi­cate (https) only shows that the con­nec­tion is encrypted. It does not prove that the site is le­git­i­mate.
  • Check for spelling or layout errors: Many phishing sites now look pro­fes­sion­al, but faulty text or in­con­sis­tent design can still be a warning sign.

Technical tools such as password managers add another layer of pro­tec­tion. They usually auto-fill login details only on the exact domain you have saved, which can help alert you to typo domains created through ty­posquat­ting.

Domain Transfer
Transfer your domain, hassle free
  • Zero downtime
  • Free SSL
  • $0 transfer fee, plus great offers

Reviewers

Go to Main Menu