---
id: "typosquatting"
kind: "glossary-term"
title: "typosquatting"
language: "en"
category: "Security and abuse"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/typosquatting/"
translations:
  es: "https://tldlog.com/es/glosario/typosquatting/"
  de: "https://tldlog.com/de/glossar/typosquatting/"
  fr: "https://tldlog.com/fr/glossaire/typosquatting/"
  it: "https://tldlog.com/it/glossario/typosquatting/"
  pt-BR: "https://tldlog.com/pt/glossario/typosquatting/"
  ru: "https://tldlog.com/ru/glossariy/taypskvotting/"
  zh-Hans: "https://tldlog.com/zh/cihui/cuopin-yuming-qiangzhu/"
---

# typosquatting

Registering domains that are misspellings of well-known names or brands, to catch users who type mistakes. It is a form of cybersquatting, and the domains are often used for ads, phishing or malware. Trademark owners often challenge them under the UDRP.

Typosquatting is registering a misspelling of a well-known domain name, so that people who mistype an address or misread a link end up on a site, or receive mail, controlled by someone else. It is a form of cybersquatting. Trademark owners can challenge these names, and registrars must act when they are used for phishing or malware.

## What typosquatting is

The World Intellectual Property Organization (WIPO) describes it as registering a variation of a trademark, typically a common, obvious or intentional misspelling. As of October 2026, WIPO Overview 3.1, the summary of how WIPO panels decide UDRP cases, says:

- A misspelled name is normally confusingly similar to the mark, the first UDRP element, because the mark is still recognizable in it.
- Panels normally read the misspelling itself as a sign of intent to confuse, usually confirmed by what the site shows.
- For a well-known mark, especially an invented one, merely registering a typo can create a presumption of bad faith.

Not every misspelled domain is unlawful: panels decide case by case. In a decision dated 28 December 2018 (WIPO case DCO2018-0034), about a .co name that replaced the "i" in BOEHRINGER INGELHEIM with an "l", the panel found that swapping one letter did not prevent confusing similarity, and ordered the name transferred to the trademark owner.

## Variants: lookalikes, combosquatting and bitsquatting

"Lookalike domain" is the umbrella term. WIPO lists the variations its panels see:

1. adjacent keyboard letters;
2. similar-looking characters, such as numbers used as letters;
3. letters that look alike in some fonts;
4. non-Latin or accented characters (a homograph attack);
5. swapped letters or numbers;
6. added words or numbers;
7. plays on the mark, such as abbreviations.

Combosquatting is the mark spelled correctly plus an extra word. Panels hold that an added term, whether descriptive, geographical, pejorative or meaningless, does not prevent confusing similarity if the mark is recognizable.

The same name under another TLD is also a lookalike. Panels ignore the TLD when comparing, but a TLD that matches the brand's line of business can point to intent.

Bitsquatting needs no human mistake: the name differs from a very busy name by one bit, the smallest unit of computer data, and the error comes from devices. Artem Dinaburg first described it in 2011. It is a subset of typosquatting and matters only for names with very large traffic.

## Why attackers use it

- Traffic and advertising, attracting users for commercial gain through confusion with a mark, one of the UDRP's examples of bad faith.
- Phishing, identity theft, malware and counterfeits. WIPO panels hold that such uses never give legitimate interests in a name.
- Email fraud with no website, such as fake job offers or false invoices sent to a company's customers.
- Copycat versions of the real site.

## How to detect it

A brand owner can generate the variations on WIPO's list for its names, check which are registered, and watch new registrations. Two common protections leave gaps:

- **Trademark Claims.** A mark recorded in the TMCH triggers a notice when a matching name is registered in a new gTLD. As of October 2026, under the 2012 rules only an "identical match" counts, so typos and mark-plus-word names trigger no notice.
- **DMARC.** It protects a company's exact domain; [RFC 9989](https://www.rfc-editor.org/rfc/rfc9989.txt) says it does not address visually similar domain names, so mail from a lookalike is outside its reach.

Every one-bit variant of a name is easy to list, but most turn out to be legitimate or ordinary typosquatting.

## What you can do: legal and technical responses

- **Report abuse.** Since 5 April 2024, gTLD registrars and registries must act promptly on actionable evidence of DNS abuse, which includes phishing and malware (as of October 2026). A name that is merely confusing is a trademark matter, not DNS abuse.
- **UDRP.** The complainant proves three elements and normally pays the fees. As of October 2026, the only remedies are transfer or cancellation.
- **URS.** For clear cases only. As of October 2026, a successful complaint suspends the name for the rest of its registration period, without transfer.
- **.es names.** A separate .es out-of-court procedure, mandatory for the holder, covers speculative or abusive registrations ([Orden ITC/1542/2005](https://www.boe.es/buscar/doc.php?id=BOE-A-2005-8902)).
- **Prevention.** Defensive registration of obvious variants, and recording the mark in the TMCH, knowing that, as noted above, its notices cover only exact matches.

Which route fits depends on the facts; a registrar, registry or lawyer can advise.

## An example

A company owns the mark EXAMPLE and uses example.com. Someone registers exmaple.example, with two letters swapped, and emails invoices from it to the company's customers. There is no website.

- Swapped letters are on WIPO's list, and panels recognize deceptive invoices as a bad-faith use even without a website.
- If the emails also seek account or login details, that is phishing, and a gTLD registrar must act on actionable evidence.
- DMARC on example.com would not stop the emails, which come from another domain.

## Sources

- [WIPO Overview 3.1](https://www.wipo.int/en/web/amc/domain-name-disputes/overview/index)
- [Uniform Domain Name Dispute Resolution Policy](https://www.icann.org/resources/pages/policy-2024-02-21-en)
- [Uniform Rapid Suspension System (URS)](https://newgtlds.icann.org/sites/default/files/procedure-21feb24-en.pdf)
- [gTLD Applicant Guidebook, 2012](https://newgtlds.icann.org/sites/default/files/guidebook-full-04jun12-en.pdf)
- [ICANN advisory on DNS abuse obligations](https://www.icann.org/en/contracted-parties/advisories/documents/advisory-compliance-with-dns-abuse-obligations-in-the-registrar-accreditation-agreement-and-the-registry-agreement-05-02-2024-en)
- [Bitsquatting: an introduction](https://gnso.icann.org/sites/default/files/filefield_40215/presentation-bitsquatting-roberts-15jul13-en.pdf)

## related terms

- [cybersquatting](https://tldlog.com/glossary/cybersquatting/)
- [UDRP](https://tldlog.com/glossary/udrp/)
- [phishing](https://tldlog.com/glossary/phishing/)
- [homograph attack](https://tldlog.com/glossary/homograph-attack/)
