typosquatting
Registering domains that are misspellings of well-known names or brands, to catch users who type mistakes. It is a form of cybersquatting Registering a domain in bad faith to profit from another's trademark. Full definition of cybersquatting, and the domains are often used for ads, phishing Impersonating a trusted party to steal data, often with look-alike domains. Full definition of phishing or malware Harmful software, often spread or controlled using domain names. Full definition of malware. Trademark owners often challenge them under the UDRP Uniform Domain-Name Dispute-Resolution Policy ICANN's out-of-court process for trademark disputes over domain names. Full definition of UDRP.
- category
- Security and abuse
Typosquatting is registering a misspelling of a well-known domain name A readable internet name made of labels separated by dots. Full definition of domain name, so that people who mistype an address or misread a link end up on a site, or receive mail, controlled by someone else. It is a form of cybersquatting. Trademark owners can challenge these names, and registrar A company that registers domain names for customers with the registry. Full definition of registrar must act when they are used for phishing or malware.
What typosquatting is
The World Intellectual Property Organization (WIPO World Intellectual Property Organization The United Nations agency whose center handles many domain name disputes. Full definition of WIPO) describes it as registering a variation of a trademark, typically a common, obvious or intentional misspelling. As of October 2026, WIPO Overview WIPO's guide to how panels usually decide common UDRP questions. Full definition of WIPO Overview, the summary of how WIPO panel The one or three independent experts who decide a domain dispute. Full definition of panel decide UDRP cases, says:
- A misspelled name is normally confusingly similar to the mark, the first UDRP element, because the mark is still recognizable in it.
- Panels normally read the misspelling itself as a sign of intent to confuse, usually confirmed by what the site shows.
- For a well-known mark, especially an invented one, merely registering a typo can create a presumption of bad faith Intent to take unfair advantage of another's trademark through a domain name. Full definition of bad faith.
Not every misspelled domain is unlawful: panels decide case by case. In a decision dated 28 December 2018 (WIPO case DCO2018-0034), about a .co name that replaced the “i” in BOEHRINGER INGELHEIM with an “l”, the panel found that swapping one letter did not prevent confusing similarity, and ordered the name transferred to the trademark owner.
Variants: lookalikes, combosquatting and bitsquatting
“lookalike domain A domain designed to be mistaken for that of a known brand or organization. Full definition of lookalike domain” is the umbrella term. WIPO lists the variations its panels see:
- adjacent keyboard letters;
- similar-looking characters, such as numbers used as letters;
- letters that look alike in some fonts;
- non-Latin or accented characters (a homograph attack Using look-alike characters to make a fake domain look real. Full definition of homograph attack);
- swapped letters or numbers;
- added words or numbers;
- plays on the mark, such as abbreviations.
combosquatting Registering a brand name combined with an extra word to deceive users. Full definition of combosquatting is the mark spelled correctly plus an extra word. Panels hold that an added term, whether descriptive, geographical, pejorative or meaningless, does not prevent confusing similarity if the mark is recognizable.
The same name under another TLD top-level domain The last part of a domain name, after the final dot. Full definition of TLD is also a lookalike. Panels ignore the TLD when comparing, but a TLD that matches the brand’s line of business can point to intent.
bitsquatting Registering domains one flipped bit away from popular names to catch misdirected traffic. Full definition of bitsquatting needs no human mistake: the name differs from a very busy name by one bit, the smallest unit of computer data, and the error comes from devices. Artem Dinaburg first described it in 2011. It is a subset of typosquatting and matters only for names with very large traffic.
Why attackers use it
- Traffic and advertising, attracting users for commercial gain through confusion with a mark, one of the UDRP’s examples of bad faith.
- Phishing, identity theft, malware and counterfeits. WIPO panels hold that such uses never give legitimate interest A GDPR ground for processing personal data, weighed against the registrant's privacy rights. Full definition of legitimate interest in a name.
- Email fraud with no website, such as fake job offers or false invoices sent to a company’s customers.
- Copycat versions of the real site.
How to detect it
A brand owner can generate the variations on WIPO’s list for its names, check which are registered, and watch new registrations Domains newly created in a period, also called adds or creates. Full definition of new registrations. Two common protections leave gaps:
- Trademark Claims. A mark recorded in the TMCH Trademark Clearinghouse A database of verified trademarks used for sunrise and claims in new gTLDs. Full definition of TMCH triggers a notice when a matching name is registered in a new gTLD A generic top-level domain added to the internet through ICANN's New gTLD Program. Full definition of new gTLD. As of October 2026, under the 2012 rules only an “identical match” counts, so typos and mark-plus-word names trigger no notice.
- DMARC Domain-based Message Authentication, Reporting and Conformance A DNS-published policy telling mail receivers how to treat email that fails authentication. Full definition of DMARC. It protects a company’s exact domain; RFC 9989, opens another website in a new tab says it does not address visually similar domain names, so mail from a lookalike is outside its reach.
Every one-bit variant of a name is easy to list, but most turn out to be legitimate or ordinary typosquatting.
What you can do: legal and technical responses
- Report abuse. Since 5 April 2024, gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD registrars and registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry must act promptly on actionable evidence The level of proof that obliges a registry or registrar to act on DNS abuse. Full definition of actionable evidence of DNS abuse Harmful use of domains, defined in ICANN contracts as five specific threats. Full definition of DNS abuse, which includes phishing and malware (as of October 2026). A name that is merely confusing is a trademark matter, not DNS abuse.
- UDRP. The complainant The party that files a domain dispute, usually a trademark owner. Full definition of complainant proves three elements and normally pays the fees. As of October 2026, the only remedies are transfer or cancellation.
- URS Uniform Rapid Suspension System A fast procedure that suspends clearly infringing domains, mainly in new gTLDs. Full definition of URS. For clear cases only. As of October 2026, a successful complaint suspends the name for the rest of its registration Obtaining the right to use a domain name for a set period. Full definition of registration period, without transfer.
- .es names. A separate .es out-of-court procedure, mandatory for the holder, covers speculative or abusive registrations (Orden ITC/1542/2005, opens another website in a new tab).
- Prevention. defensive registration A domain registered only to keep others from having it. Full definition of defensive registration of obvious variants, and recording the mark in the TMCH, knowing that, as noted above, its notices cover only exact matches.
Which route fits depends on the facts; a registrar, registry or lawyer can advise.
An example
A company owns the mark EXAMPLE and uses example.com. Someone registers exmaple.example, with two letters swapped, and emails invoices from it to the company’s customers. There is no website.
- Swapped letters are on WIPO’s list, and panels recognize deceptive invoices as a bad-faith use even without a website.
- If the emails also seek account or login details, that is phishing, and a gTLD registrar must act on actionable evidence.
- DMARC on example.com would not stop the emails, which come from another domain.
Sources
- WIPO Overview 3.1, opens another website in a new tab
- Uniform Domain Name Dispute Resolution Policy, opens another website in a new tab
- Uniform Rapid Suspension System (URS), opens another website in a new tab
- gTLD Applicant Guidebook, 2012, opens another website in a new tab
- ICANN advisory on DNS abuse obligations, opens another website in a new tab
- Bitsquatting: an introduction, opens another website in a new tab