# What is Typosquatting?

> Typosquatting is the registration of lookalike domain names based on misspellings, keyboard slips, or visual confusion with legitimate names — capturing mistyped traffic or supporting phishing and impersonation.

- Canonical URL: https://yellowcube.eu/glossary/typosquatting/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Variants exploit predictable errors: omitted or doubled letters, transposed characters, wrong top-level domains, homoglyphs that render similarly, and plausible brand-plus-word combinations. Harvested traffic ranges from casual mistyping to targeted spear-phishing destinations built to be nearly indistinguishable from the real service.

Defensive work splits between the namespace and the user. Organizations monitor for registrations resembling their names and brands, use registrar and takedown channels against abusive registrations, and protect against the inbound side — DNS filtering, certificate-transparency monitoring, email anti-spoofing, and awareness that an address that looks “close enough” is the attack.

### Key points

- **Variant families:** Misspellings, transpositions, dropped or doubled characters, alternate TLDs, homoglyph substitutions, and brand-plus-service compound names.
- **Defensive coverage:** Watch new-domain registrations and certificate transparency logs for name variants, pre-register the most-abused forms where proportionate, and pursue registrar, UDRP, or hosting takedown paths.
- **Inbound protection:** Filter known lookalike domains in web and email controls, validate DMARC to blunt domain-spoofed mail, and treat certificate-bearing lookalikes as higher-risk signals.
- **Important limitation:** A similar domain is not automatically abusive — legitimate variants, defensive registrations, and unrelated businesses exist. Registration similarity is a signal for investigation and, where warranted, a legal process, not proof of malicious intent.

### Related terms

[Cybersquatting](<https://yellowcube.eu/glossary/cybersquatting/>) · [Pharming](<https://yellowcube.eu/glossary/pharming/>) · [Phishing](<https://yellowcube.eu/glossary/phishing/>) · [Domain Name System (DNS) hijacking](<https://yellowcube.eu/glossary/domain-name-system-hijacking/>) · [Domain Name System (DNS)](<https://yellowcube.eu/glossary/domain-name-system/>)

### Sources

[ICANN SSAC SAC040: Measures to Protect Registration Services Against Misuse](https://www.icann.org/en/groups/ssac/documents/sac-040-en.pdf) · [MITRE ATT&CK T1583.001: Acquire Infrastructure — Domains](https://attack.mitre.org/techniques/T1583/001/) · [CISA, NSA, FBI, MS-ISAC, Phishing Guidance: Stopping the Attack Cycle at Phase One](https://www.cisa.gov/sites/default/files/2025-03/Phishing%20Guidance%20-%20Stopping%20the%20Attack%20Cycle%20at%20Phase%20One%20508.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

