What Is Typosquatting? Lookalike Domains
What Is Typosquatting?
Typosquatting is the practice of registering domain names that are slight misspellings or variations of popular, legitimate domains — to catch people who mistype a web address or to impersonate the real site. The name comes from "typo" (a typing mistake) and "squatting" (occupying something). When you accidentally type a popular site's address with a small error, you might land on a typosquatted domain instead. These lookalike domains are used for various malicious purposes. This guide explains what typosquatting is, the risks, and how to protect yourself, in plain terms.
How Typosquatting Works
Typosquatting exploits common typing mistakes:
Registering lookalike domains: Attackers register domains that closely resemble legitimate ones — common misspellings, missing or transposed letters, different extensions (.com vs .net), added or removed characters, or visually similar characters.
Catching typos: When someone mistypes the real domain (a very common occurrence), they may land on the typosquatted domain instead of the intended site.
Impersonation: Typosquatted domains often imitate the real site's appearance to deceive visitors into thinking they are on the legitimate site.
Examples of variations: Common techniques include misspellings (a common letter swapped), adjacent-key errors, missing letters, doubled letters, and using different domain extensions.
What Typosquatting Is Used For
Typosquatted domains serve various malicious or opportunistic purposes:
Phishing: Impersonating a legitimate site (especially login pages) to steal credentials when visitors enter them, thinking they are on the real site. This is a major use.
Malware distribution: Tricking visitors into downloading malware from a site they believe is legitimate.
Scams: Deceiving visitors with fake offers, fraud, or scams on the impersonating site.
Ad revenue: Some typosquatted domains simply show ads to monetize mistyped traffic.
Brand impersonation: Damaging or exploiting a brand by impersonating it.
The most dangerous uses are phishing and malware, where landing on a convincing fake site can compromise you.
Related: Lookalike Domains in Email and Links
Typosquatting connects to broader lookalike-domain deception:
In phishing emails: Attackers use lookalike domains in phishing emails and links, making malicious URLs appear legitimate at a glance (e.g., a slightly-off domain in a link).
Homograph attacks: Some attacks use visually similar characters (e.g., characters from other alphabets that look like Latin letters) to create domains that look identical to legitimate ones — a sophisticated variation.
The common thread: All exploit the fact that people often do not scrutinize domains carefully, trusting a familiar-looking address.
How to Protect Yourself from Typosquatting
You can protect yourself with careful habits:
Type carefully and check: Type web addresses carefully, and check the address bar to confirm you are on the correct domain, especially before entering sensitive information.
Use bookmarks: Bookmark important sites (banking, email, frequently-used accounts) and access them via bookmarks rather than typing, eliminating typo risk.
Scrutinize links: Before clicking links (especially in emails), check where they actually lead by hovering or inspecting the URL, watching for lookalike domains.
Look closely at domains: Examine domains carefully for misspellings, extra/missing characters, or odd extensions, particularly on login or payment pages.
Be cautious with sensitive actions: Before logging in or entering payment information, double-check you are on the genuine site, since typosquatted sites target exactly these moments.
Use security tools: Browsers and security tools that warn about known malicious or suspicious sites provide some protection.
Watch for the phishing context: Since typosquatting often serves phishing, the usual anti-phishing vigilance (not trusting links, verifying sites) protects you.
Frequently Asked Questions
What is typosquatting in simple terms?
Typosquatting is registering domain names that are slight misspellings or variations of popular legitimate domains — to catch people who mistype a web address or to impersonate the real site. The name combines "typo" and "squatting." Attackers register lookalike domains using common misspellings, missing or transposed letters, different extensions, or visually similar characters, so that when someone mistypes a popular site's address, they may land on the fake domain instead. These lookalike domains are then used for phishing, malware, scams, or ad revenue.
What are typosquatted domains used for?
Various malicious or opportunistic purposes. The most dangerous are phishing (impersonating a legitimate site, especially login pages, to steal credentials) and malware distribution (tricking visitors into downloading malware from a seemingly legitimate site). Others include scams with fake offers or fraud, showing ads to monetize mistyped traffic, and brand impersonation. Because typosquatted domains often imitate the real site's appearance, visitors may not realize they are on a fake site, making phishing and malware uses particularly dangerous.
How can I protect myself from typosquatting?
Type web addresses carefully and check the address bar to confirm the correct domain, especially before entering sensitive information. Bookmark important sites (banking, email) and access them via bookmarks rather than typing, eliminating typo risk. Scrutinize links before clicking (especially in emails) by checking where they actually lead, examine domains closely for misspellings or odd extensions, and double-check you are on the genuine site before logging in or entering payment information. Since typosquatting often serves phishing, general anti-phishing vigilance — not trusting links and verifying sites — also protects you.
Conclusion
Typosquatting is the practice of registering domain names that are slight misspellings or variations of popular legitimate domains, to catch people who mistype a web address or to impersonate the real site. Attackers register lookalike domains using common misspellings, missing or transposed letters, different extensions, or visually similar characters, exploiting the fact that mistyping is common and people often do not scrutinize domains carefully. These domains serve malicious purposes — most dangerously phishing (stealing credentials on impersonating login pages) and malware distribution, along with scams, ad revenue, and brand impersonation. Typosquatting connects to broader lookalike-domain deception in phishing emails and sophisticated homograph attacks using visually identical characters. You can protect yourself by typing addresses carefully and checking the address bar, bookmarking important sites and using the bookmarks, scrutinizing links before clicking, examining domains closely for irregularities, and double-checking you are on the genuine site before sensitive actions. By understanding how typosquatting works and adopting these careful habits, you can avoid the lookalike domains designed to catch your typos and deceive you.