Typosquatting.ai
RESPONSE

What to Do When Someone Typosquats Your Domain: 4 Steps

What to do if someone typosquats your domain: verify it is not yours, preserve evidence, block it, report it to the registrar and blocklists, then dispute it.

by Omar Kandil9 September 2026updated 23 September 202610 min read

First, rule out your own organisation

A surprising share of lookalikes are defensive registrations, marketing microsites, or a regional team's forgotten campaign domain. Check your domain inventory and ask the people who buy domains before treating anything as hostile. A takedown request against your own asset wastes goodwill with the registrar.

Two cheap checks settle most of these. If the registrar and the nameservers match the ones your real domain uses, the name is very likely yours. If the registration predates the brand, it is very likely somebody else's and always was. Both come from RDAP, the standardised replacement for WHOIS, and neither involves touching the domain.

Preserve evidence before it changes

Record the date and time, the RDAP response (registrar, creation date, status codes, nameservers), and the DNS answers for A, AAAA, MX and NS. If a passive scanning service already holds a capture of the site, save the reference. Phishing infrastructure rotates quickly, so the record you keep today may be the only one that shows the domain was live.

  1. Write down the time of observation, with the timezone.
  2. Save the full RDAP response, not a summary of it.
  3. Save the DNS answers for A, AAAA, MX and NS as returned.
  4. Save any existing passive scan reference, rather than generating new traffic to the host.
  5. Keep the original message intact, headers included, if the domain arrived in one.

Decide what the domain is doing

A registered name that does not resolve is a different problem from one serving a login page or configured to receive mail. Mail records with no website point towards business email compromise or reply-to fraud. A resolving site needs a passive check, not a visit from your own network. Match the response to the harm you can evidence.

What the records showWhat it is likely to beProportionate response
Registered, no delegationHeld, possibly defensively, possibly for laterRecord it and re-check. Nothing to report yet
Resolves, no mailA site of some kind, content unknownPassive check, then report if the evidence supports it
Mail configured, no siteCorrespondence fraud rather than a phishing pageWarn finance and the teams who handle invoices
Resolves and mail configured, registered recentlyThe combination that most often precedes an active campaignTreat as the first item in the queue
Certificate issued recentlySomeone prepared for traffic over HTTPSA supporting fact, never a finding on its own

Block it yourself first

Everything that follows depends on somebody else acting. Your own controls take minutes and protect your own staff, the people most likely to be targeted. Do these before you send the first report.

  • Mail gateway. Add the domain, and its xn-- form if it is internationalised, to the inbound block or quarantine list, and flag any message whose display name matches an internal person but whose address is external.
  • DNS filter. Add the domain to the blocklist on the resolver your staff use, so that a click on a link resolves to nothing. Include subdomains, since a login page is often served from one.
  • Browser policy. Managed browsers accept a URL blocklist through enterprise policy. Push the domain to it, which stops the page opening even on a device that bypasses the corporate resolver.
  • Finance process. Tell accounts payable the name exists and that no change to payment details is accepted from it, or from anywhere, without a call to a number already on file.

Report to the parties who can act

The registrar is identified in the RDAP record and, under section 3.18 of ICANN's 2013 Registrar Accreditation Agreement, must maintain an abuse contact, take reasonable and prompt steps to investigate and respond appropriately to abuse reports, and publish its handling procedures. The hosting provider behind the IP address can remove content. Browser and mail providers accept phishing reports that protect users while other processes run. Send the same evidence pack to each, and keep the timestamps.

  • The registrar, from the RDAP record, for the registration itself.
  • The hosting provider, from the address the name resolves to, for the content.
  • Browser and mail safe-browsing programmes, which protect people quickly without waiting for anyone else.
  • Your own customer-facing teams, so that the first person who asks about it gets a straight answer.

Where to report a typosquatted domain

These endpoints feed the blocklists most browsers, mail clients and security products consult. A report to any of them protects strangers as well as your own staff, and none requires a legal claim to the name.

EndpointWhat it feedsHow to submit
Google Safe BrowsingWarnings in Chrome, Firefox, Safari and many mail clientsThe Report a Page to Google Safe Browsing form
Microsoft SmartScreenWarnings in Edge, Outlook and WindowsThe Report an unsafe site form; sign in with a personal or corporate account
APWGA clearing house shared with member institutionsForward the message as an attachment to reportphishing@apwg.org
PhishTankA collaborative clearing house used by many productsRegister, then submit the suspected phish
NCSC (UK)The UK takedown serviceThe Report a scam website form; forward emails to report@phishing.gov.uk
Your national CERTNational takedown and warning servicesFind the team in the FIRST member directory

What an abuse report should contain

Abuse desks work through volume, and the reports that get actioned are the ones that need no follow-up questions. Give the recipient everything required to verify the claim without asking you for it.

  1. The exact domain, in its ASCII form.
  2. What you are alleging, stated plainly, and what evidence supports it.
  3. The records you preserved, with the times you collected them.
  4. Your relationship to the brand being impersonated, and your contact details.
  5. What you are asking for, whether that is suspension, removal of content, or simply a record of the report.

When the registrar ignores you

Some registrars act within a day. Some never reply. If a well-founded report has gone unanswered, three routes remain, and they can run in parallel.

First, ICANN Contractual Compliance. ICANN's complaint page lists a registrar's failure to display abuse contacts, to investigate and respond to an abuse report, or to take mitigation action against DNS abuse as grounds for a complaint, and provides an Abuse/DNS Abuse (Registrar) form. A compliance complaint does not take the domain down, but it obliges the registrar to answer.

Second, the hosting provider, which controls the content and can remove a page regardless of the registrar. Third, a dispute, which does not depend on the registrar's goodwill at all.

When to escalate to a formal dispute

A dispute decides who should hold a name; an abuse report asks a provider to act on conduct. They answer different questions, and the second is usually faster. When the name itself is the problem, four routes exist.

The UDRP applies to every generic top-level domain; all ICANN-accredited registrars must follow it. Under paragraph 4(a) the complainant must show that the domain is identical or confusingly similar to a mark in which it has rights, that the holder has no rights or legitimate interests in it, and that it was registered and is being used in bad faith. The remedies under paragraph 4(i) are cancellation or transfer. WIPO's fee for one to five names before a single panelist is USD 1,500, or USD 4,000 for a three-member panel, and its guide says a case without procedural issues should normally complete within two months.

The Uniform Rapid Suspension System was implemented for the New gTLD Program as a lower-cost, faster path for the most clear-cut cases; whether an ending is covered depends on its registry agreement. The burden is clear and convincing evidence, the registrant has a fourteen-day response period, and the procedure sets a goal of a determination within three business days of examination beginning. The remedy is suspension for the balance of the registration period, not transfer. Fees are set per provider; ADNDRC publishes USD 360 for one to five names.

In the United States, the Anticybersquatting Consumer Protection Act, 15 U.S.C. 1125(d), makes a person liable to a mark owner if they have a bad faith intent to profit from the mark and register, traffic in or use a domain identical or confusingly similar to it. A court may order forfeiture, cancellation or transfer, and under section 1117(d) the owner may elect statutory damages of USD 1,000 to USD 100,000 per domain name. It is litigation, with the cost and time that implies.

Country-code registries run their own schemes. For .uk, WIPO's page for the Dispute Resolution Service records that disputes filed on or after 7 July 2026 are administered by WIPO, that mediation begins within three working days of the complainant's reply and runs ten working days before the parties are invited to pay for an expert decision, and that the fees are GBP 750 for an expert decision and GBP 200 for a summary decision. These are legal processes; involve counsel before filing.

RouteApplies toFiling costTypical timeOutcome
UDRP at WIPOAll generic top-level domainsUSD 1,500 (1 to 5 names, one panelist)About two monthsTransfer or cancellation
URSEndings covered by the New gTLD ProgramSet per provider; ADNDRC USD 360 (1 to 5 names)14-day response, then a 3-business-day goalSuspension for the rest of the registration
.uk DRS via WIPO.uk names, filings from 7 July 2026GBP 750 expert decision, GBP 200 summaryMediation starts within 3 working days, runs 10Expert decision on the complaint
ACPA, US federal courtMarks protected in the United StatesLitigation costsMonths to yearsTransfer, cancellation, damages up to USD 100,000 per name

What not to do

Most of the damage done in response to a lookalike is self-inflicted, and all of it is avoidable.

  • Do not visit the site from a corporate network to see what is on it.
  • Do not enter credentials anywhere on it, including deliberately incorrect ones.
  • Do not contact the registrant directly to negotiate. It raises the price and can harm a later dispute.
  • Do not state publicly that a domain is phishing before the evidence supports the claim.
  • Do not let the report be the last step, because a suspended name can be re-registered when it drops.

Close the loop and keep watching

Tell customer-facing teams what to say if someone reports the domain. Record the outcome, then re-check after a few weeks, because suspended domains are sometimes re-registered when they drop. If this is not a one-off, plan ongoing monitoring.

That is what a checker is for. Typosquatting.ai generates candidates from about twenty pattern families across about 180 endings, resolves them over DNS, and gathers its evidence from registry RDAP, DNS over HTTPS, certificate transparency logs and passive urlscan.io search without ever connecting to a suspect site; on the Pro plan every finding is re-checked daily and the certificate logs are searched every 30 minutes.

Common questions

what should I do if someone typosquats my domain
Confirm it is not one of your own registrations, preserve the RDAP and DNS records with a timestamp, block the name at your gateway and resolver, report it to the registrar's abuse contact and the safe-browsing programmes, and escalate to a dispute if you hold trademark rights.
how do I report a typosquatted domain
Send the domain, your evidence and what you are asking for to the registrar's abuse contact from the RDAP record, to the hosting provider, and to Google Safe Browsing, Microsoft SmartScreen, APWG, PhishTank and your national CERT. In the UK, use the NCSC form.
how much does a UDRP complaint cost
WIPO's fee for one to five domain names decided by a single panelist is USD 1,500, rising to USD 4,000 for a three-member panel. Legal fees are extra, and a case without procedural issues normally completes within about two months.
what is the difference between UDRP and URS
The UDRP applies to all generic top-level domains and can transfer or cancel the name, with a case taking about two months. URS was implemented for the New gTLD Program, sets a clear and convincing standard, aims for a determination within days, and only suspends the name for the rest of its registration.
what happens if the registrar ignores my abuse report
File a complaint with ICANN Contractual Compliance using its Abuse/DNS Abuse (Registrar) form, which covers a registrar's failure to respond to abuse reports. Ask the hosting provider to remove the content in parallel, and escalate to a dispute if you have trademark rights.

Sources and further reading

  1. ICANN: Registration Data Access Protocol (RDAP)
  2. ICANN: 2013 Registrar Accreditation Agreement
  3. ICANN: Submitting a Complaint to ICANN Contractual Compliance
  4. ICANN: Uniform Domain-Name Dispute-Resolution Policy (UDRP)
  5. ICANN: UDRP policy text
  6. ICANN: Uniform Rapid Suspension (URS)
  7. ICANN: Rights Protection Mechanisms and Dispute Resolution Procedures
  8. ICANN: URS Procedure (1 March 2013)
  9. ADNDRC: URS fees
  10. WIPO: Schedule of Fees under the UDRP
  11. WIPO: Guide to the UDRP
  12. WIPO: Domain Name Dispute Resolution Service for .UK
  13. WIPO: Schedule of Fees for .UK
  14. 15 U.S.C. 1125(d): Cyberpiracy prevention (Legal Information Institute)
  15. 15 U.S.C. 1117(d): Statutory damages for cyberpiracy (Legal Information Institute)
  16. Google Safe Browsing: Report a Page
  17. Microsoft Security Intelligence: Report an unsafe site
  18. APWG: Report Phishing Emails
  19. PhishTank
  20. NCSC: Report a scam website
  21. NCSC: Report a scam email
  22. FIRST: member teams directory
  23. Typosquatting.ai: methodology and data sources