Typosquatting.ai
WHO IS BEHIND THIS

About Typosquatting.ai

Domain security should start with a clear answer, and a clear answer starts with knowing who is giving it.

by Typosquatting.ai ResearchLast updated 6 October 2026

Who we are

Typosquatting.ai is an independent lookalike-domain checker. It generates the names that resemble a domain, resolves every one, and reports those that exist with the public records behind them. It is the whole product rather than a preview of a larger one. It is run by Cyber Deans Ltd, a company registered in England and Wales under company number 12784136.

How the site is funded

Which domains look like mine is the first question most teams ask, and it should not require a sales call. A check needs no account and no payment, and the site carries no advertising, no affiliate links, and no resale of the domains you check. Paid plans fund it: Pro adds a watchlist with daily re-checks and email alerts, Business adds an organisation, and Enterprise adds takedown requests sent by our team. None of them is a condition of seeing results.

  • No advertising, and no sponsored placement inside results.
  • No affiliate links to registrars, and no commission on a name you decide to buy.
  • No resale or sharing of the domains you check.
  • No gate in front of a result you have already run.

Who writes what you read

Every guide and educational page carries a named author, with publication and last-updated dates. Authors write from operational experience running detection and takedown work. The author named at the top of a page is accountable for every sentence in it, including the technical claims and the paragraph saying what the evidence cannot establish.

There is no separate reviewer and this site does not claim one. A page carries one name, and that name is the one to hold it to. Technical claims rest on primary sources such as ICANN policy, IETF standards and provider documentation, and those are cited at the foot of each page so the claim can be checked rather than trusted.

Published is the date a page first appeared. Updated changes only when the substance changes, never to make a page look recent.

Where the evidence comes from

Nothing in a report is produced by visiting the domain being checked. Every field is read from a public source, which is what makes the result repeatable by someone who does not trust us.

SourceWhat we take from it
Registry RDAPRegistrar, registration date, status codes, nameservers
DNS over HTTPSAddresses, mail routing, delegation
Certificate transparency logsNames that a certificate authority has issued for
Passive scan historyEarlier public observations of a host, where they already exist

How we communicate risk

We show the evidence, explain the signals, and preserve uncertainty. Registered does not mean malicious. No record does not guarantee availability. A low-signal finding does not mean a brand is safe. The exact rules behind each label are published on the methodology page.

A review priority is a position in a queue. It answers the question of what to look at first, and it does not answer the question of who did what, which no registry record can settle.

What we will not claim

We publish no detection-accuracy percentages, because we have not run an evaluation we would be comfortable defending in public. Risk labels are documented heuristics, not a proprietary score. A similar domain is never described as malicious on the strength of similarity alone. Nothing on this site is legal advice.

  • No customer counts, logos or testimonials that we cannot evidence.
  • No certifications, awards or credentials we do not hold.
  • No claim to find every impersonating domain, because no method can.
  • No description of a feature that is not built and working.

How to check what we say

Everything above is meant to be verifiable rather than reassuring. The routes are short.

  1. Read the methodology page, which publishes the patterns, the sources and the rule behind every label.
  2. Read the editorial policy, which sets out who writes, which sources count and how dates are used.
  3. Follow the sources at the foot of any guide and check the claim against the primary document.
  4. Run a check on a domain you already know well, and compare what comes back with what you know.
  5. Tell us where we are wrong, using the contact page.

Corrections and contact

To report an error in a result or an article, use the contact page and include the page address. We correct mistakes when they are reported and note material updates on the page itself.

Security researchers will find the disclosure policy and security contact on the contact page and in security.txt.

Sources and further reading

  1. Google Search Central: Creating helpful, reliable, people-first content
  2. RFC 9116: security.txt
  3. ICANN: Registration Data Access Protocol (RDAP)
  4. Cloudflare: DNS over HTTPS JSON API
  5. RFC 6962: Certificate Transparency
  6. Typosquatting.ai: methodology and data sources