Typosquatting.ai
STRATEGY

Defensive Domain Registration: Is It Worth It, and How Many?

Every defensive registration is a renewal cost forever. That is the discipline the decision needs. Illustrative lookalikes in this guide use the reserved .test ending, so that no real registration is named.

by Omar Kandil16 September 2026updated 23 September 202612 min read

Defensive domain registration is registering variants of your own name so that nobody else can, accepting that only a small fraction of the possible variants can ever be bought.

This guide covers how large the space of confusable names is, which of them to register, watch or ignore, whether defensive registration is worth its cost against a dispute or an incident, how many domains a small business and a larger brand should hold, what the blocking services cover, and how to keep a defensive portfolio from rotting.

The size of the space, measured

Generate every candidate across about twenty pattern families for a six-letter name such as example.com and the count comes to 3,001. That figure excludes most scripts, most subdomains of public hosting platforms, and every keyword somebody might invent tomorrow, so it is a floor rather than a ceiling.

The distribution matters more than the total. The largest families are not typing mistakes at all: a brand combined with a keyword, under the original ending or another one, accounts for well over half the candidates. Those families grow with the dictionary, so no purchasing decision closes them. The typing mistakes, which are the names people actually register defensively, are about a sixth of the space.

Pattern familyExample for example.comCandidates
Keyword and different endingexample-login.test663
Keyword compoundlogin-example.test544
Keyword with a typoexmaple-login.test384
Hosting platform nameexample.pages.dev347
Dictionary keywordexample-login.test276
Different domain endingexample.net196
Typing mistakes, all kindsexmaple.test, ezample.test525
Lookalike characters and small familiesexаmple.com (Cyrillic a), ex-ample.test66
The rows sum to 3,001. Typing mistakes combine substitution, missing, added, inserted, transposed and repeated characters. The last row combines lookalike characters, bit flips, prefixes, hyphenation, subdomain splits and plurals. Defensive registration is not pointless. It must be a short list chosen on cost of absence, not a coverage exercise.

Register, watch or ignore?

No registration strategy solves this, because the space of confusable names is larger than any budget, and the families that dominate the count are keyword combinations and alternative endings rather than typing mistakes, which are exactly the ones nobody would have thought to register. So the question is not how much you can buy. It is which small set is genuinely dangerous, and how you find out about everything else early enough to matter.

The table below is the whole decision.

CategoryDecisionWhy
The endings customers assume you useRegisterA customer typing your name with the wrong ending is a mistake you can remove permanently, once, for the price of a registration
The one or two typos closest on a keyboardRegisterA very small set, a high proportion of accidental traffic, and cheap to hold
Names you already own but cannot account forInventory firstA large share of first-check findings turn out to be the organisation's own property, and until you know which, every review is repeated work
Keyword combinations and hosting platform namesWatchToo numerous to own, and this is the category that actually appears in phishing messages
Lookalike character variantsWatch, or blockRegistering one does nothing about the next one; the top tier of a blocking service covers the set
Names held by unrelated legitimate businessesRecord and leaveShort words collide across industries and countries, and pursuing them costs goodwill and produces nothing

Which names justify the renewal

A defensive registration is worth its cost when somebody else holding that name would cause a specific, foreseeable harm.

Assumed endings
The endings your market expects. A business known in the United Kingdom under a .com should hold the .co.uk. A customer who guesses wrongly and lands somewhere else is a harm you can price.
Nearest typos
The one or two variations closest to your name on a keyboard, particularly a dropped character in a short brand that people type frequently.
Offline-advertised names
Anything printed on packaging, vehicles, posters or invoices, where a reader cannot inspect a destination before acting.
Machine-resolved names
Names that appear in configuration: mail domains, package registries, internal tooling. A human reading a link may notice something wrong. A mail server will not.
Names you already lost control of
If a variation was yours and lapsed, re-acquiring it is usually cheaper than explaining it later.

Which names to skip

Most of them, deliberately.

  • Long-tail endings nobody in your market uses. Holding a name under an ending your customers have never seen protects nobody.
  • Keyword combinations. The space is unbounded and buying a few creates a false sense of coverage.
  • Deep misspellings that require two or more edits. They are rarely typed and rarely registered.
  • Names an unrelated business already holds legitimately. That is a dispute question, not a purchase.
  • Anything you would not renew in five years. A defensive registration that lapses quietly enters the market with your history attached.

Is defensive registration worth it?

Put numbers on it, because the argument is usually made with adjectives. Suppose a name renews at 15 a year in your currency, a plausible assumption for an ordinary ending and a poor one for a premium ending or a restricted country code. Ten defensive names held for five years cost 750, plus the hour a year somebody spends keeping the list honest.

Set that against a dispute. A single UDRP complaint covering one to five domain names, decided by a single panellist at WIPO, carries a filing fee of USD 1,500 before anybody has paid for the drafting, and WIPO will not proceed until the fee is received. A three-member panel for the same complaint is USD 4,000. The remedy at the end is limited to cancellation of the name or its transfer to you, with no money judgment and no costs. So one dispute over one name costs more than a decade of holding ten names, and the dispute only starts after the harm has begun.

Set it against an incident and the comparison stops being close. A customer who typed the wrong ending and paid an invoice to somebody else, a mail domain that a supplier's server resolved without a human reading it, a lapsed name that came back as a phishing site with your history attached: any of those costs more in a week than the portfolio costs in a decade.

It is also the whole case. Past the short list, each additional name protects against a less foreseeable harm for the same renewal. The eleventh name is rarely worth it. The hundredth almost never is. The arithmetic favours a small portfolio and a monitoring routine, not a large portfolio and a feeling of safety.

How many domains should you register?

There is no universal number, but there is a method: count the names whose absence would cause a specific harm you can describe, and stop there. Two worked examples.

A small business: five to eight names
The exact name on the two or three endings your customers assume, typically the ending you trade under plus the national one and .com if that is not already it. The one or two typos nearest your name on a keyboard. And the domain you send mail from, if it differs from the website, because a mail domain is resolved by machines that never notice a misspelling. A business trading as example.com in the United Kingdom would hold example.com, example.co.uk, exmaple.test and, if it mails from a separate name, that name. Nothing else.
A larger brand: twenty to forty, then blocking
The same logic repeated across each product name customers type independently, each market's assumed ending, and each name printed on physical material. Past that point the list grows faster than the harm, which is where a blocking service or a Trademark Clearinghouse record starts to make sense, because it covers hundreds of endings for one fee. The names a larger brand should not buy are the keyword compounds, however many appear in a check, because that family is unbounded and the ones that matter appear in monitoring.

Blocking services: what they cover and where they fail

Three mechanisms sit between registering a name and merely watching it. Each stops a registration before it happens, across many endings, for a single fee, and each has a boundary worth knowing before paying.

Trademark Clearinghouse
A database of verified trademarks that ICANN's new generic endings consult. Recording a mark costs USD 155 per record per year on the basic fee structure. It gives priority access to the name during each new ending's Sunrise period, and a Trademark Claims notification to the rights holder after somebody registers a matching name. It does not block anything by itself, and it covers exact matches of the mark, not typos.
DPML
The Domains Protected Marks List from Identity Digital blocks the exact match of a trademark, or a term containing it, across the 300 or more endings that registry operates. It requires a valid Signed Mark Data file issued by the Trademark Clearinghouse. A blocked name is inactive: it cannot host a site or receive mail unless the holder asks for an override. It is sold by the year or for multi-year terms at a price well above a single registration, and the plus tier adds misspellings, premium names and Unicode variants. It covers one registry's endings and nothing else.
GlobalBlock
A unified blocking service that restricts registration of verified exact-match names by third parties across hundreds of endings from several registries, 841 extensions on its own count, including some the brand would not be eligible to register in. The plus tier extends the block to an unlimited number of homoglyph variations. Names that are already registered cannot be blocked until they are deleted or expire, so it protects the future, not the present.
The common failure is the same for all three. They cover the exact mark and, at the top tier, its close variants. They do not cover the keyword compounds that dominate what appears in phishing messages, because example-login is not a variant of example. Blocking removes the long tail of endings from the problem. It leaves the long tail of words, which is what monitoring is for.

Registering and monitoring answer different questions

Registration removes a specific name from the market permanently and costs a renewal every year. Monitoring covers every name you did not buy, costs the same regardless of how many there are, and tells you when one appears.

Registration handles the small set where the harm of absence is certain, and monitoring handles the large set where the harm is possible. A programme that only registers is spending heavily on the safe part of the problem. A programme that only monitors will one day explain why a customer's obvious guess belonged to somebody else.

Keeping a defensive portfolio healthy

Defensive names rot in characteristic ways, and the fixes are procedural.

  1. Keep them in the same registrar account as the primary name, or at least in an inventory a security team can read.
  2. Set them to auto-renew against a payment method and a mailbox that outlive any individual.
  3. Point them somewhere deliberate. A redirect to your main site is fine. A registrar parking page carrying advertisements is your brand endorsing whatever it serves.
  4. Publish mail authentication records on them that refuse mail, so a name you own cannot be used to send in your name.
  5. Review the list annually against what you still sell and where. Defensive registrations accumulate for products that no longer exist.

How this interacts with a check

The first run against an established brand usually shows a number of findings that turn out to be the organisation's own defensive names. That is the inventory problem surfacing, not a detection failure. This site's checker tags a variation registered through your registrar and served by your nameservers as possibly yours for exactly this reason, and it reads only public records to do it: registry RDAP, DNS over HTTPS, certificate transparency logs and passive urlscan.io search, never the suspect site itself.

Settling those once, and marking them, is the highest-value hour in the exercise. Everything afterwards is a shorter list.

Common questions

Is defensive domain registration worth it?
For a short list, yes: the endings customers assume, the nearest typos and the mail domain cost less over a decade than one dispute over one name, and far less than one incident. Past that list, each name protects against a less likely mistake for the same renewal, and monitoring covers the rest.
How many domains should I register for my business?
A small business usually needs five to eight: the exact name on two or three endings, one or two nearest typos, and the mail domain. A larger brand repeats that per product and market, then uses a blocking service rather than buying further endings.
Should I register all the typos of my domain?
No. Typing mistakes are about a sixth of the confusable space and most are never typed. Register the one or two closest on a keyboard and watch the rest, because a typo that acquires mail records is what needs attention, and monitoring shows that.
What is the difference between defensive registration and domain blocking?
Registration buys one name under one ending and you can use it. Blocking pays a registry or a service to refuse anyone the exact match across hundreds of endings, and the blocked names are inactive. Blocking covers endings cheaply; it does not cover keyword compounds.
Does defensive registration stop phishing?
It removes a few specific names from the market. Phishing mostly uses keyword compounds and lookalikes that no portfolio can contain, so registration reduces accidental traffic to a handful of names and does little about deliberate impersonation. Mail authentication and monitoring do the rest.

Sources and further reading

  1. WIPO: Schedule of fees under the UDRP
  2. WIPO: Guide to the UDRP
  3. ICANN: Uniform Domain Name Dispute Resolution Policy
  4. ICANN: Trademark Clearinghouse
  5. Trademark Clearinghouse: Pricing
  6. EuroDNS: Guide to DPML
  7. 101domain: DPML defensive domain blocking
  8. GlobalBlock
  9. GoDaddy Help: About GlobalBlock and GlobalBlock+
  10. Typosquatting.ai: methodology and data sources

Keep reading in Domain protection