What Is Typosquatting? How Lookalike Domains Attack Your Brand (2026)
Almost every phishing attack starts with a domain that looks just enough like a real one to fool a hurried customer. That is typosquatting — and the lookalike domains it produces are the launchpad for credential theft, payment fraud, and brand impersonation.
This guide explains what typosquatting is, the different kinds of lookalike domains attackers use, why they are dangerous, and how to detect and stop them in 2026.
What is typosquatting?
Typosquatting — also called URL hijacking or brandjacking — is the practice of registering domain names that closely resemble a legitimate brand's domain. The goal is to catch people who mistype a web address, misread a link, or simply trust a name that looks familiar. Once a visitor lands on the lookalike, it can host a fake login page, a cloned checkout, malware, or scam ads.
The types of lookalike domains
Typosquatting is a family of techniques. The common variants include:
- Character typos: swapped, doubled, omitted, or transposed letters — for example "gooogle.com" or "exmaple.com".
- Homoglyph / IDN homograph: characters that look identical to Latin letters, such as a Cyrillic "а" standing in for a Latin "a", so the name looks right but resolves elsewhere.
- TLD swaps: the real name on a different extension — ".co" instead of ".com", or a new gTLD.
- Combosquatting: the real brand plus an extra word, like "brand-login.com" or "secure-brand.com".
- Bitsquatting: a one-bit change from the real domain that a small fraction of devices resolve by hardware error.
A single campaign often mixes several of these, registering dozens of permutations at once.
Why typosquatting is dangerous for brands
Lookalike domains weaponize the trust users place in your brand. They host fake login and checkout pages that steal credentials and payment data, send phishing emails that survive a quick glance, intercept mistyped traffic, and damage your reputation when victims blame the real brand. Because registering a domain costs almost nothing, attackers can stand up many variants faster than a team can chase them by hand — which is why typosquatting sits at the center of brand impersonation.
How to detect typosquatting domains
Effective detection layers several signals so a lookalike is caught early:
- Permutation generation: expand your domain into its typo, homoglyph, TLD-swap, and combosquatting variants and watch for new registrations.
- Certificate transparency: new TLS certificates for brand-adjacent domains are an early sign a clone is being stood up.
- Registration age: a freshly registered lookalike is far more suspicious than an old one.
- Content scanning: check suspicious domains for cloned pages, your logo, and credential-harvesting forms.
This is exactly what continuous domain intelligence and monitoring is built for. To verify a single suspect domain, see how to check if a domain is a phishing site.
How to stop typosquatting
Defense combines proactive and reactive moves:
- Monitor continuously for new lookalike registrations rather than checking occasionally.
- Register the obvious variants defensively — common typos and key TLDs — so attackers cannot.
- Take down active abuse: confirm phishing or impersonation, capture evidence, and report to the registrar and host.
When a lookalike is actively phishing, move it straight into a takedown service, and follow our guide to reporting abuse to a registrar or host to get it removed.
Frequently asked questions
What is typosquatting?
Typosquatting is the practice of registering domain names that closely resemble a legitimate brand's domain — using common typos, swapped characters, extra words, or different extensions — to trick users who mistype a URL or misread a link. The lookalike domains are then used for phishing, scams, ad fraud, or malware.
What is the difference between typosquatting and a homoglyph attack?
Typosquatting relies on typing or reading mistakes, such as 'gooogle.com'. A homoglyph (or IDN homograph) attack uses characters that look identical to Latin letters — for example a Cyrillic 'а' in place of a Latin 'a' — so the domain looks correct to the eye even though it is a different name entirely. Both produce lookalike domains used for impersonation.
Why is typosquatting dangerous for brands?
Lookalike domains turn the trust users place in your brand into an attack. They host fake login and checkout pages that steal credentials and payment data, send phishing emails that pass a quick glance, and damage your reputation when victims blame the real brand. Because registering domains is cheap, attackers can spin up many variants at once.
How do I detect typosquatting domains?
Generate the typo, homoglyph, and keyword permutations of your domain and monitor for new registrations, watch certificate transparency logs for brand-adjacent certificates, and scan suspicious domains for cloned content. Automated domain monitoring surfaces these lookalikes far faster than manual checks.
How do I stop a typosquatting domain?
Confirm the domain is being used for phishing or impersonation, capture evidence, and report it to the registrar and hosting provider for takedown, escalating to ICANN or a dispute process where appropriate. Defensive registration of the most obvious variants and continuous monitoring reduce how often you have to react.
Sources and further reading
- ICANN — About Phishing: background on phishing and the role of domain names.
- CISA — Recognize and Report Phishing: official US guidance on spotting and reporting phishing.
- APWG — Phishing Activity Trends Reports: the Anti-Phishing Working Group's data on phishing domains and targets.
About the author
Eric Wallace
Security Researcher at PhishDown
Eric researches phishing detection, domain intelligence, and brand-protection takedowns at PhishDown. He writes about how organizations can find and remove phishing sites, lookalike domains, and brand impersonation before they reach customers.
View all articles by Eric Wallace →Why you can trust this guide
- Written and reviewed by PhishDown's security research team.
- Grounded in how phishing detection, domain intelligence, and takedowns actually work in practice, not marketing claims.
- References authoritative sources including CISA, the APWG, ICANN, and the FBI's IC3.
- Last reviewed and updated July 1, 2026.
Related Articles
Catch lookalike domains before they strike
PhishDown scans domains for typosquatting and phishing signals and connects confirmed threats to takedown. Explore domain intelligence or get in touch.