What to Do When Someone Typosquats Your Domain: 4 Steps
What to do if someone typosquats your domain: verify it is not yours, preserve evidence, block it, report it to the registrar and blocklists, then dispute it.
First, rule out your own organisation
A surprising share of lookalikes are defensive registrations, marketing microsites, or a regional team's forgotten campaign domain. Check your domain inventory and ask the people who buy domains before treating anything as hostile. A takedown request against your own asset wastes goodwill with the registrar.
Two cheap checks settle most of these. If the registrar and the nameservers match the ones your real domain uses, the name is very likely yours. If the registration predates the brand, it is very likely somebody else's and always was. Both come from RDAP, the standardised replacement for WHOIS, and neither involves touching the domain.
Preserve evidence before it changes
Record the date and time, the RDAP response (registrar, creation date, status codes, nameservers), and the DNS answers for A, AAAA, MX and NS. If a passive scanning service already holds a capture of the site, save the reference. Phishing infrastructure rotates quickly, so the record you keep today may be the only one that shows the domain was live.
- Write down the time of observation, with the timezone.
- Save the full RDAP response, not a summary of it.
- Save the DNS answers for A, AAAA, MX and NS as returned.
- Save any existing passive scan reference, rather than generating new traffic to the host.
- Keep the original message intact, headers included, if the domain arrived in one.
Decide what the domain is doing
A registered name that does not resolve is a different problem from one serving a login page or configured to receive mail. Mail records with no website point towards business email compromise or reply-to fraud. A resolving site needs a passive check, not a visit from your own network. Match the response to the harm you can evidence.
| What the records show | What it is likely to be | Proportionate response |
|---|---|---|
| Registered, no delegation | Held, possibly defensively, possibly for later | Record it and re-check. Nothing to report yet |
| Resolves, no mail | A site of some kind, content unknown | Passive check, then report if the evidence supports it |
| Mail configured, no site | Correspondence fraud rather than a phishing page | Warn finance and the teams who handle invoices |
| Resolves and mail configured, registered recently | The combination that most often precedes an active campaign | Treat as the first item in the queue |
| Certificate issued recently | Someone prepared for traffic over HTTPS | A supporting fact, never a finding on its own |
Block it yourself first
Everything that follows depends on somebody else acting. Your own controls take minutes and protect your own staff, the people most likely to be targeted. Do these before you send the first report.
- Mail gateway. Add the domain, and its xn-- form if it is internationalised, to the inbound block or quarantine list, and flag any message whose display name matches an internal person but whose address is external.
- DNS filter. Add the domain to the blocklist on the resolver your staff use, so that a click on a link resolves to nothing. Include subdomains, since a login page is often served from one.
- Browser policy. Managed browsers accept a URL blocklist through enterprise policy. Push the domain to it, which stops the page opening even on a device that bypasses the corporate resolver.
- Finance process. Tell accounts payable the name exists and that no change to payment details is accepted from it, or from anywhere, without a call to a number already on file.
Report to the parties who can act
The registrar is identified in the RDAP record and, under section 3.18 of ICANN's 2013 Registrar Accreditation Agreement, must maintain an abuse contact, take reasonable and prompt steps to investigate and respond appropriately to abuse reports, and publish its handling procedures. The hosting provider behind the IP address can remove content. Browser and mail providers accept phishing reports that protect users while other processes run. Send the same evidence pack to each, and keep the timestamps.
- The registrar, from the RDAP record, for the registration itself.
- The hosting provider, from the address the name resolves to, for the content.
- Browser and mail safe-browsing programmes, which protect people quickly without waiting for anyone else.
- Your own customer-facing teams, so that the first person who asks about it gets a straight answer.
Where to report a typosquatted domain
These endpoints feed the blocklists most browsers, mail clients and security products consult. A report to any of them protects strangers as well as your own staff, and none requires a legal claim to the name.
| Endpoint | What it feeds | How to submit |
|---|---|---|
| Google Safe Browsing | Warnings in Chrome, Firefox, Safari and many mail clients | The Report a Page to Google Safe Browsing form |
| Microsoft SmartScreen | Warnings in Edge, Outlook and Windows | The Report an unsafe site form; sign in with a personal or corporate account |
| APWG | A clearing house shared with member institutions | Forward the message as an attachment to reportphishing@apwg.org |
| PhishTank | A collaborative clearing house used by many products | Register, then submit the suspected phish |
| NCSC (UK) | The UK takedown service | The Report a scam website form; forward emails to report@phishing.gov.uk |
| Your national CERT | National takedown and warning services | Find the team in the FIRST member directory |
What an abuse report should contain
Abuse desks work through volume, and the reports that get actioned are the ones that need no follow-up questions. Give the recipient everything required to verify the claim without asking you for it.
- The exact domain, in its ASCII form.
- What you are alleging, stated plainly, and what evidence supports it.
- The records you preserved, with the times you collected them.
- Your relationship to the brand being impersonated, and your contact details.
- What you are asking for, whether that is suspension, removal of content, or simply a record of the report.
When the registrar ignores you
Some registrars act within a day. Some never reply. If a well-founded report has gone unanswered, three routes remain, and they can run in parallel.
First, ICANN Contractual Compliance. ICANN's complaint page lists a registrar's failure to display abuse contacts, to investigate and respond to an abuse report, or to take mitigation action against DNS abuse as grounds for a complaint, and provides an Abuse/DNS Abuse (Registrar) form. A compliance complaint does not take the domain down, but it obliges the registrar to answer.
Second, the hosting provider, which controls the content and can remove a page regardless of the registrar. Third, a dispute, which does not depend on the registrar's goodwill at all.
When to escalate to a formal dispute
A dispute decides who should hold a name; an abuse report asks a provider to act on conduct. They answer different questions, and the second is usually faster. When the name itself is the problem, four routes exist.
The UDRP applies to every generic top-level domain; all ICANN-accredited registrars must follow it. Under paragraph 4(a) the complainant must show that the domain is identical or confusingly similar to a mark in which it has rights, that the holder has no rights or legitimate interests in it, and that it was registered and is being used in bad faith. The remedies under paragraph 4(i) are cancellation or transfer. WIPO's fee for one to five names before a single panelist is USD 1,500, or USD 4,000 for a three-member panel, and its guide says a case without procedural issues should normally complete within two months.
The Uniform Rapid Suspension System was implemented for the New gTLD Program as a lower-cost, faster path for the most clear-cut cases; whether an ending is covered depends on its registry agreement. The burden is clear and convincing evidence, the registrant has a fourteen-day response period, and the procedure sets a goal of a determination within three business days of examination beginning. The remedy is suspension for the balance of the registration period, not transfer. Fees are set per provider; ADNDRC publishes USD 360 for one to five names.
In the United States, the Anticybersquatting Consumer Protection Act, 15 U.S.C. 1125(d), makes a person liable to a mark owner if they have a bad faith intent to profit from the mark and register, traffic in or use a domain identical or confusingly similar to it. A court may order forfeiture, cancellation or transfer, and under section 1117(d) the owner may elect statutory damages of USD 1,000 to USD 100,000 per domain name. It is litigation, with the cost and time that implies.
Country-code registries run their own schemes. For .uk, WIPO's page for the Dispute Resolution Service records that disputes filed on or after 7 July 2026 are administered by WIPO, that mediation begins within three working days of the complainant's reply and runs ten working days before the parties are invited to pay for an expert decision, and that the fees are GBP 750 for an expert decision and GBP 200 for a summary decision. These are legal processes; involve counsel before filing.
| Route | Applies to | Filing cost | Typical time | Outcome |
|---|---|---|---|---|
| UDRP at WIPO | All generic top-level domains | USD 1,500 (1 to 5 names, one panelist) | About two months | Transfer or cancellation |
| URS | Endings covered by the New gTLD Program | Set per provider; ADNDRC USD 360 (1 to 5 names) | 14-day response, then a 3-business-day goal | Suspension for the rest of the registration |
| .uk DRS via WIPO | .uk names, filings from 7 July 2026 | GBP 750 expert decision, GBP 200 summary | Mediation starts within 3 working days, runs 10 | Expert decision on the complaint |
| ACPA, US federal court | Marks protected in the United States | Litigation costs | Months to years | Transfer, cancellation, damages up to USD 100,000 per name |
What not to do
Most of the damage done in response to a lookalike is self-inflicted, and all of it is avoidable.
- Do not visit the site from a corporate network to see what is on it.
- Do not enter credentials anywhere on it, including deliberately incorrect ones.
- Do not contact the registrant directly to negotiate. It raises the price and can harm a later dispute.
- Do not state publicly that a domain is phishing before the evidence supports the claim.
- Do not let the report be the last step, because a suspended name can be re-registered when it drops.
Close the loop and keep watching
Tell customer-facing teams what to say if someone reports the domain. Record the outcome, then re-check after a few weeks, because suspended domains are sometimes re-registered when they drop. If this is not a one-off, plan ongoing monitoring.
That is what a checker is for. Typosquatting.ai generates candidates from about twenty pattern families across about 180 endings, resolves them over DNS, and gathers its evidence from registry RDAP, DNS over HTTPS, certificate transparency logs and passive urlscan.io search without ever connecting to a suspect site; on the Pro plan every finding is re-checked daily and the certificate logs are searched every 30 minutes.
Common questions
- what should I do if someone typosquats my domain
- Confirm it is not one of your own registrations, preserve the RDAP and DNS records with a timestamp, block the name at your gateway and resolver, report it to the registrar's abuse contact and the safe-browsing programmes, and escalate to a dispute if you hold trademark rights.
- how do I report a typosquatted domain
- Send the domain, your evidence and what you are asking for to the registrar's abuse contact from the RDAP record, to the hosting provider, and to Google Safe Browsing, Microsoft SmartScreen, APWG, PhishTank and your national CERT. In the UK, use the NCSC form.
- how much does a UDRP complaint cost
- WIPO's fee for one to five domain names decided by a single panelist is USD 1,500, rising to USD 4,000 for a three-member panel. Legal fees are extra, and a case without procedural issues normally completes within about two months.
- what is the difference between UDRP and URS
- The UDRP applies to all generic top-level domains and can transfer or cancel the name, with a case taking about two months. URS was implemented for the New gTLD Program, sets a clear and convincing standard, aims for a determination within days, and only suspends the name for the rest of its registration.
- what happens if the registrar ignores my abuse report
- File a complaint with ICANN Contractual Compliance using its Abuse/DNS Abuse (Registrar) form, which covers a registrar's failure to respond to abuse reports. Ask the hosting provider to remove the content in parallel, and escalate to a dispute if you have trademark rights.
Sources and further reading
- ICANN: Registration Data Access Protocol (RDAP)
- ICANN: 2013 Registrar Accreditation Agreement
- ICANN: Submitting a Complaint to ICANN Contractual Compliance
- ICANN: Uniform Domain-Name Dispute-Resolution Policy (UDRP)
- ICANN: UDRP policy text
- ICANN: Uniform Rapid Suspension (URS)
- ICANN: Rights Protection Mechanisms and Dispute Resolution Procedures
- ICANN: URS Procedure (1 March 2013)
- ADNDRC: URS fees
- WIPO: Schedule of Fees under the UDRP
- WIPO: Guide to the UDRP
- WIPO: Domain Name Dispute Resolution Service for .UK
- WIPO: Schedule of Fees for .UK
- 15 U.S.C. 1125(d): Cyberpiracy prevention (Legal Information Institute)
- 15 U.S.C. 1117(d): Statutory damages for cyberpiracy (Legal Information Institute)
- Google Safe Browsing: Report a Page
- Microsoft Security Intelligence: Report an unsafe site
- APWG: Report Phishing Emails
- PhishTank
- NCSC: Report a scam website
- NCSC: Report a scam email
- FIRST: member teams directory
- Typosquatting.ai: methodology and data sources