What is typosquatting?
Typosquatting refers to the deliberate registration of domains that look almost identical to well-known web addresses and contain only minimal typing errors. The goal is to catch users who mistype a web address and redirect them to fake or misleading websites.
How does typosquatting work?
Typosquatting relies on small changes to a domain name. A letter may be omitted, swapped, or replaced with a visually similar character. Homoglyph attacks are especially difficult to spot. In these cases, attackers might use the digit ‘0’ instead of the letter ‘O’ or Unicode characters from other alphabets. These variations are barely noticeable to the human eye.
Classic examples often involved misspelled names of major search engines or online shops. Today, typosquatting increasingly targets SaaS services, cloud platforms, AI tools, and payment providers. Fake login pages that imitate ChatGPT, Microsoft 365, or well-known crypto platforms show how professional these attacks have become. The goal is to redirect accidental traffic and profit from it. In more serious cases, attackers use highly convincing login pages to steal credentials or payment information. For companies, every typosquatting incident can mean a potential loss of customers.
Typosquatting is often confused with cybersquatting, but the intent is different. Rather than blocking or reselling a brand domain, typosquatting aims to capture traffic with domain names that differ only slightly from the original.
Common types of typosquatting
Criminals use several forms of typosquatting to mislead users. These are the most common types:
- Typos: Transposed letters, doubled characters, or missing characters are among the most common variants. Attackers create domains that differ only slightly from a well-known address. Many major brands now register these versions themselves and use a redirect to send users to the main domain before the addresses can be misused.
- Spelling mistakes: Not every incorrect domain comes from typing too quickly. Permanently misspelled brand or product names are also deliberately registered as a domain. These variants can generate significant traffic, especially for popular brands.
- Alternative spellings: Different spellings of common words can also create opportunities for typosquatting. For example, a business using
www.travellerdeals.commay also need to consider whether users might enterwww.travelerdeals.com. - Hyphen domains: Domains with and without hyphens are especially vulnerable. Adding or removing a hyphen creates a separate address. Typosquatters also combine well-known brands with additions such as ‘shop’, ‘online’, or ‘service’ to suggest an official connection.
- Incorrect domain endings: The large number of new top-level domains has increased the risk further. A brand registered under .com, for example, can also be registered under .shop, .online, or .web. The .co ending is especially popular because it closely resembles .com. If you only register one TLD, you risk leaving alternative endings open to misleading or fraudulent use.
| Variant | Description | Example | Main risk |
|---|---|---|---|
| Classic typo | Transposed, doubled, or missing letters | amazom.ie instead of amazon.ie
|
Traffic interception, redirection to ad pages |
| Spelling mistake | Permanently misspelled brands | linkdin.com instead of linkedin.com
|
Deception, data theft |
| Alternative spelling | Different spellings of the same term | colourprint.com vs. colorprint.com
|
Customer loss, brand dilution |
| Hyphen variant | Adding or removing hyphens | online-bank-login.com
|
Misleading login pages |
| Brand addition | Adding trust-building terms | delivery-tracking.com
|
Phishing, theft of personal data |
| Different TLD | Same name with a different ending | company-support.co instead of company-support.com
|
Login abuse |
| Homoglyph attack | Replacement with visually similar characters | rnicrosoft.com (rn instead of m)
|
Hard-to-detect phishing |
| IDN/Unicode abuse | Use of foreign alphabet characters with an identical appearance | аррle.com (Cyrillic characters)
|
Highly professional scam sites |
Typosquatting in SaaS and AI environments
Typosquatting has become much more professional in recent years. Instead of relying on simple ad redirects, attackers now focus on high-value accounts and sensitive login details. Cloud services, project management tools, payment platforms, and AI applications with paid subscriptions are especially attractive targets.
Attackers register domains that look almost identical to official login pages. They combine common typos with trust-building terms such as ‘secure’, ‘verify’, or ‘account’ and often use valid TLS certificates. This can make the page look legitimate at first glance.
Typical scenarios include:
- Fake login portals for project management or collaboration tools
- Fake invoice pages from parcel delivery services
- Imitated payment or wallet portals
- Imitated AI platforms with supposed upgrade notices
- Domains with minimal character changes, such as 1 instead of l or 0 instead of O
AI-supported website generation makes it easier to create convincing copies of real provider websites in a very short time. As a result, typosquatting is no longer just a way to capture accidental traffic. It has become a key part of modern phishing strategies and creates concrete risks for companies:
- Loss of potential customers
- Damage to brand image and reputation
- Increased support and security costs
- Possible data exposure due to compromised login credentials
What is the legal situation with typosquatting in Ireland?
Typosquatting is not automatically illegal in Ireland. However, registering and using typo domains can violate trademark rights, amount to passing off, or qualify as an abusive domain registration. The key question is usually whether the domain creates confusion, exploits another company’s reputation, or was registered in bad faith.
Trademark law
Trademark law is one of the main legal bases used against typosquatting in Ireland. If a typo domain is confusingly similar to a registered trademark and is likely to mislead users, this may constitute trademark infringement.
Possible actions may include:
- Demanding that the domain holder stop using the domain
- Seeking transfer or cancellation of the domain
- Claiming damages or injunctive relief in certain cases
Cases are particularly clear when the typo domain is used for competing goods or services, phishing, or misleading commercial activity.
Passing off
Even without a registered trademark, businesses in Ireland may rely on the legal concept of passing off. This applies when someone uses a domain name in a way that misleads users into believing there is a connection with another business or brand.
To succeed in a passing off claim, a business generally has to show:
- goodwill or reputation in the name or brand,
- a misleading representation by the domain holder, and
- resulting damage or likely damage.
Domain dispute procedures
For .ie domains, disputes are handled through the IEDR’s Dispute Resolution Policy (DRP) rather than through court proceedings. Complaints are administered by the World Intellectual Property Organization (WIPO) Arbitration and Mediation Center, which appoints an independent panel to decide the case.
A complainant generally has to show that:
- the domain name is identical or misleadingly similar to a protected identifier (such as a trademark or company name) in which they have rights,
- the registrant has no rights in law or legitimate interest in the domain name, and
- the domain was registered or is being used in bad faith.
Where a complaint is upheld, the IEDR implements the WIPO decision and transfers the disputed domain to the successful complainant 21 days later, provided no legal challenge has been lodged in the meantime.
International dispute resolution
Many international domains such as .com domains may also be challenged through the Uniform Domain-Name Dispute-Resolution Policy (UDRP), often administered by WIPO.
Criminal relevance
If typo domains are used for phishing, payment fraud, malware distribution, or credential theft, criminal laws may also apply. Depending on the conduct involved, this can include fraud offences or offences under computer misuse legislation.
Typosquatting from a business and private user perspective
Typosquatting can affect both businesses and private individuals, but the risks are not the same.
| Perspective | Risk | Typical consequences | Protection approach |
|---|---|---|---|
| Businesses | Brand abuse, traffic loss, phishing under their own name | Loss of revenue, reputational damage, higher support and security costs | Domain strategy, monitoring, trademark registration, technical safeguards |
| Private individuals | Entering login credentials on fake sites | Account takeover, identity theft, financial loss | Checking URLs, password manager, two-factor authentication |
Businesses usually need to respond with a combination of strategic, technical, and legal measures. For private users, the focus is more on everyday caution and basic security practices. In both cases, typosquatting is not just a theoretical risk, but a practical security issue in everyday digital life.
How to protect yourself against typosquatting
You cannot prevent typosquatting completely. However, you can reduce the risk significantly by combining a clear domain strategy with technical safeguards and internal processes.
- Register common spelling variants early: Secure common typos, alternative spellings, relevant hyphenated versions, and important domain extensions for your brand. Frequently used typo domains can redirect to your main domain to prevent misuse.
- Reserve important domain extensions: In addition to your primary domain, register key extensions such as .ie, .com, .net, .org, or industry-specific TLDs like .shop, .store, or .online. This reduces the risk of third parties using your brand under alternative extensions.
- Use domain monitoring: Use monitoring services that scan newly registered domains for names similar to your brand. Early alerts help you respond before harmful content spreads.
- Protect your brand through trademark registration: Register your trademark nationally or internationally. A registered trademark makes it much easier to enforce your rights, for example through a UDRP proceeding or legal action.
- Strengthen DNS and email security: Add technical safeguards that make your domain infrastructure harder to abuse. These include DNSSEC to secure name resolution, as well as SPF, DKIM, and DMARC to help prevent email spoofing.
- Raise awareness among employees and customers: Train employees to recognise suspicious links and login pages. Also make it clear to customers which official domains and communication channels you use.
- Act quickly and consider legal action: If you discover an abusive domain, document its content and assess potential trademark or unfair competition claims. The faster you respond, the lower the risk of reputational damage, data misuse, or customer loss.
How to recognise a typosquatting site
Typosquatting sites are often professionally designed and technically convincing. Even so, there are common warning signs that can point to a manipulated or fake domain:
- Check the URL carefully: Look at the web address character by character. Pay attention to swapped letters, extra characters, missing letters, or lookalike combinations such as ‘rn’ instead of ‘m’ or ‘0’ instead of ‘O’.
- Watch for unusual domain extensions: Be cautious if a well-known brand suddenly appears under an unfamiliar extension such as .co, .online, or .shop.
- Look for suspicious additions in the domain: Terms such as ‘secure’, ‘verify’, ‘login’, or ‘support’ combined with a brand name are common in phishing domains.
- Be wary of login pages without context: If you land directly on a login page without actively requesting it, check the URL especially carefully.
- Pay attention to unusual redirects: Multiple automatic redirects or a URL that changes after the page loads can indicate manipulation.
- Do not rely on the certificate alone: A valid TLS certificate (https) only shows that the connection is encrypted. It does not prove that the site is legitimate.
- Check for spelling or layout errors: Many phishing sites now look professional, but faulty text or inconsistent design can still be a warning sign.
Technical tools such as password managers add another layer of protection. They usually auto-fill login details only on the exact domain you have saved, which can help alert you to typo domains created through typosquatting.