What Is Typosquatting? Examples and How to Prevent It

Typosquatting is the practice of registering domain names that are deliberate misspellings or look-alikes of a legitimate website, so that people who mistype a web address or misread a sender name land on an attacker-controlled domain instead. Names like goggle.com, arnazon.com, or paypa1.com exist to catch a slipped keystroke and impersonate a trusted brand. Because the fake domain is a real registration the attacker controls, typosquatting powers phishing, credential theft, malware delivery, and business email compromise (BEC), and it is one reason a message can look like it came from a company you know when it did not.
What is typosquatting?
Typosquatting, also called URL hijacking, is a form of domain abuse where someone registers a domain that closely resembles a well-known one and relies on human error to drive traffic to it. The bet is simple: a fraction of people typing facebook.com will fumble a letter, and a fraction of people glancing at a sender address will not notice that an m has been replaced by rn. Once a visitor arrives, the squatted domain can host a convincing copy of the real login page, serve malware, redirect to advertising, or send email that appears to come from the imitated organization.
The technique works because domains are cheap to register and the visual difference between the real name and the fake one is often a single character. A look-alike domain is not a hacked version of the original: it is a separate domain the attacker owns outright, which is exactly why defenses that protect your own domain do not automatically cover it.
How typosquatting works
Typosquatting works in three steps: an attacker generates variants of a target domain, registers the ones still available, and points them at infrastructure built to profit from the mistake. The common variant types are:
- Simple misspellings and typos, such as
goggle.comforgoogle.comoramazom.comforamazon.com. - Character transpositions, where two adjacent letters are swapped, for example
gomogle.comorfacbeook.com. - Homoglyphs and number-for-letter swaps, replacing characters that look alike, such as the digit
1for a lowercaselinpaypa1.com, orrnstanding in form. - Wrong or added top-level domains, registering the same brand name under a different extension like
.co,.net, or.orgwhen the real site uses.com. - Added or removed hyphens and words, turning
mybank.comintomy-bank.com.

Once a variant is registered, the domain earns its keep in several ways. Some pages mimic the real brand to harvest logins or payment details, some install malware on visit, and some simply run advertising or affiliate redirects that monetize the stray traffic. A single actor can register dozens of variants of one brand at once.
Why attackers use typosquatting
Attackers use typosquatting because a believable look-alike domain does most of the social-engineering work before a target reads a single word. Typosquatted domains are weaponized for a handful of overlapping goals:
- Phishing and credential theft, hosting a replica login page on the look-alike domain to capture usernames and passwords.
- Malware and drive-by downloads, using the fake page to push malicious files or exploit the browser.
- Advertising and affiliate revenue, parking the domain on ads or redirecting mistyped visitors to earn per-click income.
- Brand and reputation damage, publishing content that trades on the imitated brand's name or misleads its customers.
The same look-alike registration also enables email attacks. A domain that reads almost identically to a real one lets an attacker send messages that pass a casual glance, which is where a targeted spear phishing campaign against a named employee often begins.
Typosquatting and business email compromise
Business email compromise (BEC) is the highest-impact email use of typosquatting: a fraudster registers a look-alike domain, then impersonates an executive, supplier, or finance contact to trick an employee into wiring money or handing over sensitive data. A registered look-alike domain makes that impersonation far more convincing than a spoofed header alone, because an email from [email protected] or [email protected] can slip past someone skimming their inbox on a phone.

Because the attacker actually owns the look-alike domain, they can send mail that passes authentication checks on that domain, so basic technical filtering does not flag it as forged. This is the boundary that separates typosquatting from email spoofing: spoofing forges the From header on a domain the attacker does not control, while typosquatting registers a genuinely different domain that merely reads like the real one. Both end up in the inbox, but they require different defenses.
Typosquatting examples
Typosquatting targets the largest brands precisely because they attract the most mistyped traffic, so the biggest names have the most look-alike variants registered against them. Well-documented patterns include:
- Search and retail giants, with variants like
goggle.comandarnazon.comcatching users who slip a key while typinggoogle.comoramazon.com. - Major platforms defending their own misspellings: companies including Google, Facebook, and Adobe have registered or pursued look-alike variations of their own domains to keep them out of attacker hands.
- Payment and banking look-alikes, such as
paypa1.com, which swap a character to imitate a login users trust with money.
The pattern is consistent: the more recognizable the brand, the more variants exist, and the more valuable each mistyped visit becomes to whoever registered the fake.
Typosquatting vs cybersquatting vs combosquatting
Typosquatting, cybersquatting, and combosquatting are related but not interchangeable, and they differ in what the registered domain is trying to do. Typosquatting misspells a real domain to catch typos, cybersquatting registers a brand name in bad faith to profit from ownership, and combosquatting adds an extra word to a correctly spelled brand.
| Term | What the domain does | Example |
|---|---|---|
| Typosquatting | Misspells a real domain to catch typos and impersonate it | arnazon.com |
| Cybersquatting | Registers a brand or trademark name in bad faith, often to resell it or profit from the name | famousbrand.com held for ransom |
| Combosquatting | Combines the real brand with an extra word, no misspelling required | paypal-security.com |
Cybersquatting is largely about ownership of the name itself, and it is addressed through legal channels such as the US Anticybersquatting Consumer Protection Act (ACPA) and the WIPO Uniform Domain-Name Dispute-Resolution Policy (UDRP). Typosquatting and combosquatting lean more heavily on deception at the moment of contact, which makes detection and monitoring, not just legal action, central to defending against them.
How to detect and prevent typosquatting
You cannot block a typosquatted domain outright because someone else owns it, so prevention combines careful user habits with organizational monitoring, defensive registration, and takedowns. Microsoft's security guidance on typosquatting stresses the same split between what individuals watch for and what teams enforce.
For individual users
- Type important addresses directly or use bookmarks instead of relying on memory or search results.
- Read the full domain before you log in or click, checking for swapped letters, digits standing in for letters, and unusual extensions.
- Treat links inside unexpected email with caution, and verify the sender's exact domain rather than the display name.
For organizations and IT teams
- Defensively register key variants of your domain, including common misspellings, alternate top-level domains, and hyphenated forms, so attackers cannot.
- Monitor for look-alike registrations using certificate-transparency logs and passive DNS, which surface newly registered domains that resemble yours before they are used.
- Pursue takedowns and disputes through registrars, hosting providers, and UDRP or ACPA processes when a squatted domain targets your brand.
- Enforce email authentication on the domains you do own. Publishing SPF, DKIM, and DMARC records and moving DMARC to an enforcement policy stops attackers from forging your real domain.

One caveat matters for email specifically: DMARC alone does not stop a look-alike domain. DMARC protects the domains listed in your own records by telling receivers to reject mail that fails authentication on those names. A typosquatted domain is a separate registration the attacker controls, so it can publish its own passing SPF and DKIM records and sail through. That is why brand and domain monitoring sits alongside authentication rather than being replaced by it. If a look-alike domain starts blasting mail under your brand, recipients may report it, so it is also worth periodically running a blacklist check on your own sending domains to confirm the fallout has not reached you.
FAQs
What is typosquatting in simple terms?
Typosquatting is registering a domain that is a slight misspelling or look-alike of a real one, like goggle.com for google.com, so people who mistype an address or misread a sender land on an attacker's site instead.
What is the difference between typosquatting and cybersquatting?
Typosquatting relies on misspellings to catch mistyped traffic and impersonate a brand. Cybersquatting registers a brand or trademark name in bad faith, usually to resell it or profit from ownership of the name itself.
Is typosquatting illegal?
It can be. Brand owners can pursue squatted domains through legal frameworks such as the US Anticybersquatting Consumer Protection Act and the WIPO UDRP dispute process, though enforcement depends on trademark rights and intent.
How do I know if a domain is typosquatted?
Read the full domain character by character before acting on it, watching for swapped or doubled letters, digits standing in for letters, extra hyphens, and unexpected top-level domains. When in doubt, navigate to the site directly rather than through a link.
Does DMARC stop typosquatting?
No. DMARC protects the domains in your own records against forgery, but a typosquatted domain is a different domain the attacker owns and can authenticate on its own. Stopping look-alike domains needs monitoring, defensive registration, and takedowns in addition to DMARC.
Look-alike sender domains are a core delivery path for phishing and BEC, and the same list hygiene that protects your reputation also helps you spot mail from domains you never authorized. Run your list through BounceCheck before your next send to keep invalid and risky addresses out of your campaigns.
BounceCheck Team
The team behind BounceCheck - helping businesses verify emails and improve deliverability.


