Typosquatting.ai
PATTERNS

Types of Typosquatting: 20 Patterns With Real Examples

The permutations are mechanical. Knowing which family a finding belongs to tells you how worried to be about it. Illustrative lookalikes in this guide use the reserved .test ending, so that no real registration is named.

by Typosquatting.ai Research16 September 2026updated 23 September 202611 min read

A typosquatting pattern is a rule for deriving a confusable name from a real one, such as dropping a character, swapping two, substituting a lookalike from another script, or attaching a keyword.

This guide works through the twenty pattern families a generator produces, with an example of each, the number of candidates each yields for a six-letter domain, documented real cases in each family, and what a registered name in that family usually means when it appears in a report.

What a candidate is, and where these examples come from

A candidate is a name derived from a real domain by one rule, before anyone has checked whether it exists. Every example below is generated for example.com, a reserved name set aside for documentation, by a generator working from twenty pattern families. Running it on that one six-letter domain yields 3,001 candidates. The counts are not evenly spread, and the distribution is the first useful observation: the families that dominate are not typing mistakes but a brand combined with a keyword, or the same brand moved to a different ending.

Each family below states the rule, an example, and what a registered name in that family usually means. None of this establishes intent. A registered name in a high-risk family is a name to review early, not a finding of abuse.

Pattern familyExample for example.comCandidates
Keyword and different endingexample-login.test663
Keyword compoundlogin-example.test544
Keyword with a typoexmaple-login.test384
Hosting platform nameexample.pages.dev347
Dictionary keywordexample-login.test276
Different domain endingexample.net196
Keyboard substitutionezample.test175
Missing and added characterexmples.test154
Inserted characterexsample.test144
Lookalike charactersexаmple.com (Cyrillic a)41
Added characterexamplea.test32
Missing characterexmple.test7
Repeated characterexaample.test7
Prefixed wordmy-example.test7
Transposed charactersexmaple.test6
Hyphenated formex-ample.test6
Subdomain splitex.ample.test6
Bit-flipped characterezample.test (one bit flipped)3
Cyrillic lookalikeехаmрlе.com2
Plural formexamples.test1

Character-level mistakes

These are the families the word typosquatting was coined for. They model a hand slipping on a keyboard, and they are the smallest group by volume because a short name only has so many characters to get wrong. They are also the families behind the oldest documented cases: goggle.com, one letter away from google.com, was the site McAfee used in a 2006 web safety promotion because visiting it installed malware at the time, and nicholekidman.com, one letter added to the actress’s name, was transferred to her by a WIPO panel in 2001.

Missing character
exmple.test. One character dropped. A registered omission of a short, heavily typed name is among the most valuable variations an attacker can hold, because the mistake is common and the name is plausible.
Repeated character
exaample.test. One character doubled, modelling a key held slightly too long. goggle.com is a doubled g standing in for the second o.
Transposed characters
exmaple.test. Two adjacent characters swapped, the classic fast-typing error.
Keyboard substitution
ezample.test. A character replaced by its neighbour on a QWERTY keyboard. These names look like nonsense in isolation, which is exactly why a registered one is worth attention: nobody registers a meaningless string by accident.
Inserted character
exsample.test. An extra character added mid-word. nicholekidman.com is this family: an h inserted into a name people already misspell.
Added character
examplea.test. An extra character appended.
Missing and added character
exmples.test. Two edits at once, which widens the net at the cost of plausibility.
Plural form
examples.test. Frequently a legitimate and unrelated registration, and frequently already owned by the brand.

Visual similarity and homograph attacks

These families do not model a mistake at all. They model a glance. The name is not mistyped; it is misread, which means the attack works even when the victim pastes a link rather than typing it.

The best documented demonstration is from 2017, when the researcher Xudong Zheng registered a name spelled entirely in Cyrillic characters that rendered as apple.com in Chrome and Firefox. Visually the two domains were indistinguishable because of the font the browsers used. He reported it on 20 January 2017 and Chrome fixed its display rules in version 58 that April. A year later Brian Krebs described xn--80a7a.com, two Cyrillic characters that render as ca.com, and a lookalike of his own site that used a lowercase n with a tiny dot beneath it, a character used by several dozen scripts.

Lookalike characters
exаmple.com written with a Cyrillic a. Substituting a character from another script that renders almost identically in most fonts. The Latin a is Unicode 0061 and the Cyrillic a is 0430; to a person they look the same, to a resolver they are different names.
Cyrillic lookalike
ехаmрlе.com. The whole word rebuilt from confusable characters, the technique of the 2017 apple.com demonstration. Browsers defend against the extreme cases by displaying the Punycode form, but the defence depends on the script mix and is not absolute.
Bit-flipped character
A single bit changed in one character of the name. This models memory errors rather than human ones, and it matters for automated clients that resolve a name millions of times. A registered bit-flip of a heavily used domain is a deliberate act; nobody arrives at one by imagination.
Hyphenated form
ex-ample.test. A hyphen inserted at a word boundary, which reads as a normal styling choice.
Subdomain split
ex.ample.com. The name split so the brand appears to the left of a dot. Related and more dangerous is the case where the real brand appears as a subdomain of a name somebody else controls, which is why reading a domain from the right matters.

Brand plus keyword, also called combosquatting

This is the largest group and the one most worth understanding, because these names contain no mistake at all. The brand is spelled correctly. What has been added is a word that makes a message sound official: login, secure, support, billing, verify. Together the keyword families account for well over half the candidates generated for a single domain.

A name in this group is only convincing in context. Nobody types example-login.test by accident. They click it in a message that told them their account needs attention. Unit 42’s 2020 study of squatting domains gives the documented shape of it: secure-wellsfargo.org targeted the bank’s customers, amazon-india.online was set up to steal credentials from mobile users in India, and netflix-payments.com is the kind of name that turns up in phishing emails and scam websites to convince people they are on content the brand maintains. The same study recorded microsoft-alert.club registered on 11 June 2020 and walrmart44.com, a keyword name that also carries a transposition, distributing potentially unwanted programs.

That is why the registration date carries so much weight here: a keyword name registered years ago and parked is a different object from one registered eleven days ago with a certificate already issued.

Dictionary keyword
example-login.test. Brand plus a keyword under the original ending.
Keyword compound
login-example.test. The keyword placed first.
Keyword and different ending
example-login.test. Brand plus keyword moved to another ending, the single largest family.
Keyword with a typo
exmaple-login.test. A keyword name that also carries a spelling error, which defeats naive exact-match monitoring. walrmart44.com is a documented instance.
Prefixed word
my-example.test. A possessive or portal-style prefix, common in genuine products as well as impersonations.

Different endings and hosted names

These families keep the brand intact and change where it lives. They are the reason a brand that owns its name under one ending is not finished.

Different domain ending
example.net. The same name under another suffix. Around 180 endings are worth generating, including compound ones such as co.uk. Many of these are legitimately held by unrelated parties in other countries or industries.
Hosting platform name
example.pages.dev. The brand as a subdomain of a public hosting platform, which anybody can claim in minutes with no registration. These names need an HTTP check to confirm, because such platforms answer DNS for every possible subdomain whether or not anyone has claimed it.

Typosquatting beyond domain names

The same patterns apply wherever a name is typed and resolved by a machine. Software package registries are the clearest case. In August 2017 the npm registry removed a package called crossenv, a name one hyphen away from the popular cross-env, after a user reported that it was sending environment variables from the machine that installed it to an outside server. Around forty packages were involved in the same campaign.

A newer variant does not need a typo at all. Slopsquatting is the practice of registering a non-existent package name that a large language model may hallucinate in its output, so that someone who pastes the suggested install command gets a package that was created to be found that way. The term was coined in April 2025 by Seth Larson of the Python Software Foundation. The lesson is the same as for domains: an automated client follows the name exactly, and a name only has to exist to be resolved.

Real typosquatting cases

The table gathers the documented cases used throughout this guide, one per family where possible, so that each pattern has a real instance beside the example.com illustration. Every row is drawn from a court record, a panel decision, a browser vendor’s own report or a published investigation listed in the sources.

DomainImitatedYearWhat it did
nicholekidman.comNicole Kidman2001Adult advertising; transferred by WIPO panel
fallwell.comJerry Falwell2005Criticism site; held not to be cybersquatting
goggle.comgoogle.com2006Drive-by malware, featured by McAfee
1,100 names, e.g. dellinspirion.comDell2007Held through domain tasting; Dell sued
equifacks.com and two othersCredit bureaus2016Satire, registered by John Oliver
xn--80ak6aa92e.comapple.com2017Cyrillic homograph demonstration
xn--80a7a.comca.com2018Cyrillic lookalike reported by Krebs
secure-wellsfargo.orgWells Fargo2020Credential phishing, per Unit 42
Real brand names appear in this guide only inside these documented cases. Everything else is illustrated with example.com.

How the families rank in a report

The families are not weighted equally when a report is built. A sensible ranking puts a live HTTPS response first, then impersonation keywords, then names that are registered but not yet live, then names found in certificate logs, then names that merely resolve to an address.

The table at the top of this guide is the output of the generator behind the checker on this site, which produces 3,001 candidates for example.com from about twenty pattern families across roughly 180 endings and resolves the first 2,970 of them over DNS over HTTPS. Its review priority follows published rules: a keyword pattern only reaches the highest priority when the registration is under a year old, and a variation that shares your registrar and nameservers is tagged as possibly yours. It never connects to a suspect site; the evidence is registry RDAP, DNS, certificate transparency logs and passive urlscan.io search, as set out on the methodology page.

Using the patterns without over-reacting

The practical value of knowing the families is triage. A registered keyboard substitution or bit flip is unusual enough to look at immediately. A registered plural or alternative ending is so common that it deserves a check against your own inventory before anything else. A keyword name with a recent registration date and a certificate is the shape of something being prepared.

What none of the families supply is intent. The pattern tells you how a name was derived. Only the registration date, the infrastructure, and in the end a human decision tell you what it is for. The Falwell and John Oliver registrations above were derived by the same rules as the phishing names, and they were not phishing.

Common questions

What are the types of typosquatting?
They fall into four groups: character-level mistakes such as a dropped, doubled, swapped or neighbouring letter; visual lookalikes that substitute characters from another script; brand-plus-keyword names such as example-login.test, often called combosquatting; and the same brand under a different ending or on a public hosting platform. The keyword group produces by far the most candidates.
What is combosquatting?
Combosquatting attaches a word to a correctly spelled brand, for example secure-wellsfargo.org or netflix-payments.com, both documented by Unit 42 in 2020. Nothing is misspelled, so a reader checking for typos finds none; the name works because it arrives with a message that matches the added word.
What is a homograph attack?
A homograph attack uses characters from another script that render like the expected ones. In 2017 a name written entirely in Cyrillic displayed as apple.com in Chrome and Firefox until Chrome 58 changed its display rules. Browsers now show such names in their Punycode form, beginning xn--, when the script mix looks deceptive.
What is the most common typosquatting pattern?
By count, a brand plus a keyword under a different ending, such as example-login.test: 663 of the 3,001 candidates for example.com fall into that family, and keyword families together make up well over half. Character-level typos are a small minority by volume, though they are the ones people think of first.
Is a typosquatted domain always malicious?
No. Unit 42 classified 18.59 percent of the squatting domains it studied as malicious. The rest were parked, held for resale, registered defensively by the brand, or, as with fallwell.com and the credit bureau satire names, registered for comment. A registered name in any family is a name to review, not a finding.

Sources and further reading

  1. Unit 42: Cybersquatting: attackers mimicking domains of major brands
  2. Xudong Zheng: Phishing with Unicode domains (2017)
  3. Krebs on Security: Look-alike domains and visual confusion (2018)
  4. Wikipedia: Typosquatting
  5. WIPO decision D2000-1415: Nicole Kidman v. John Zuccarini
  6. Lamparello v. Falwell, 420 F.3d 309 (4th Cir. 2005), FindLaw
  7. The Register: Dell sits on cybersquatters (2007)
  8. npm blog: crossenv malware on the npm registry (2017)
  9. Wikipedia: Slopsquatting
  10. Unicode Technical Standard #39: Unicode Security Mechanisms (confusables)
  11. Public Suffix List
  12. RFC 5890: Internationalized Domain Names for Applications (IDNA): definitions
  13. Chromium: IDN display policy
  14. Mozilla: IDN display algorithm
  15. Typosquatting.ai: methodology and data sources

Keep reading in Typosquatting