Typosquatting.ai
DEFENCE

Should You Register Typo Domains? What Protection Works

The space of confusable names is larger than any budget. The work is choosing what to own and what to watch.

by Andrew Maged16 September 2026updated 23 September 202612 min read

Typosquatting protection is the combination of a small defensive registration set, monitoring of everything else, mail authentication, browser and legal safeguards, and a documented response process that limits what a lookalike domain can achieve.

This guide covers why buying the permutation space does not work, which names are genuinely worth registering, a worked example with real prices, a ten-point protection checklist with what each item does and does not cover, what monitoring adds, and how to decide the response before a finding.

Why you cannot register your way out

A single six-letter domain generates around three thousand candidate names under about twenty pattern families, before considering every script and every subdomain of every hosting platform. Registering that set for one brand would cost more each year than most security budgets, and it would protect one name in one spelling.

The arithmetic gets worse with brand length and with the number of endings a business operates under. It also never finishes: new endings are delegated, new hosting platforms appear, and the keyword families that dominate the candidate space expand with every word an attacker might attach.

Defensive registration is worth doing. It is not worth doing indiscriminately, and a strategy that consists only of buying names spends heavily on the safe part of the problem while leaving the dangerous part uncovered.

Should you register typo domains?

Yes, a few, and the answer is a few for a reason. The names worth buying are the ones where the cost of somebody else holding them is highest, not the ones that are cheapest to think of. Most guides on this question recommend registering the common misspellings and pointing them at the real site, which is sound as far as it goes. Where they go wrong is in implying that the list can ever be complete, or that owning it makes monitoring unnecessary.

Two facts settle it. Most registered lookalikes are not typos but keyword compounds and alternative endings, which no typo list covers. And a typo domain nobody has registered harms nobody, so the useful question is not which names could exist but which now do. Buy the handful whose loss would hurt, redirect them permanently to the real site, and watch the rest.

  • The endings your customers assume you use. If you are a .com and your market assumes .co.uk, that name being held by somebody else is a standing risk.
  • The one or two typos closest to your name on a keyboard, particularly a dropped character in a short, frequently typed brand.
  • Names you already advertise in the physical world, on packaging, vehicles or signage, where a reader cannot inspect a link before acting on it.
  • Names used by automated systems: anything a mail server, a package manager or a build pipeline resolves without a human reading it.

A worked example with numbers

Take a six-letter brand under .com. A generator working from twenty pattern families produces 3,001 candidates for it, dominated by keyword compounds, keyword names under other endings and hosting-platform names. Of the character-level families, a dropped character yields 7 candidates, a doubled character 7, a transposition 6, and a keyboard substitution 175.

Apply the criteria above and the list to buy is short: the two or three endings your market assumes, the two or three most plausible dropped or transposed characters, the plural, and perhaps one hyphenated form. Call it five to ten names. Verisign’s wholesale price for a .com registration is 10.26 US dollars a year, rising to 10.97 from 1 November 2026, and retail prices sit above that, so ten names cost in the region of one to two hundred dollars a year to hold and redirect.

Now price the alternative. Registering all 3,001 candidates at wholesale would be over thirty thousand dollars a year for the .com rows alone, many candidates sit under endings that cost several times more, and the list would be incomplete the day it was bought, because it excludes every keyword nobody thought of and every hosting platform that launches next year. Monitoring the whole space costs a subscription and covers the names that actually get registered.

The sensible split is a small portfolio plus a watch on everything else, with the money saved spent on the response process that turns a finding into an action.

OptionNames coveredApproximate yearly cost
Buy five to ten key variants5 to 10100 to 200 US dollars
Buy every candidate3,001 and growingOver 30,000 US dollars at wholesale
Monitor every candidate3,001, resolvedOne subscription
Buy a few and monitor the restAllThe first row plus a subscription

Typosquatting protection checklist

Every item below appears on somebody’s list of recommendations. Each is worth doing, and each covers less than it is usually credited with, so the second sentence of every item says what it does not do.

  1. Register the key variants. Five to ten names chosen by the criteria above, redirected to the real site. This closes the obvious typos and the endings customers assume; it does nothing about keyword compounds, homographs or hosting platforms.
  2. Record your marks with the Trademark Clearinghouse. It authenticates rights holders’ information and provides it to registries and registrars, giving priority access during a new ending’s sunrise and a notice after a matching name is registered. The notice fires on a name that matches the recorded mark, so a misspelling or a compound does not trigger it.
  3. Keep the legal routes ready. The UDRP recovers a name registered and used in bad faith for 1,500 US dollars in fees before a single panellist; the URS suspends a clear-cut case in newer generic endings for the balance of its registration; the US ACPA allows a suit with statutory damages. All three need evidence of bad faith and none is fast enough to stop a campaign in progress.
  4. Sign your zone with DNSSEC. It adds data origin authentication and data integrity to DNS answers, so a resolver can tell a forged answer for your name from a real one. It says nothing about a different name, which is what a lookalike is.
  5. Serve everything over HTTPS and publish an HSTS policy. HSTS lets a site declare itself accessible only over secure connections, which protects your own visitors from downgrade attacks. A lookalike can obtain its own valid certificate in minutes, so the padlock does not distinguish you from it.
  6. Publish and enforce SPF, DKIM and DMARC. The UK National Cyber Security Centre’s phishing guidance puts it plainly: make it harder for email from your domains to be spoofed by employing these anti-spoofing controls. They stop mail claiming to be from your exact domain; a lookalike is a different domain and passes its own checks.
  7. Train the people who handle money and credentials. The useful lesson is a habit: reach services from a bookmark, read an address from the right, and treat an unexpected request as the signal before the link is. Training reduces clicks; it does not reduce registrations.
  8. Turn on browser typo warnings where they exist. Microsoft Edge ships Website Typo Protection, on by default, which warns when it appears you have mistyped a popular domain name. It covers popular domains Microsoft has profiled, so a mid-sized brand should not assume it is on the list.
  9. Monitor the candidate space. Generate every family across every common ending, resolve the candidates, and re-check on a schedule so that a new registration, certificate or mail record reaches you within days rather than when a customer complains. Monitoring finds names; it does not decide what they are for.
  10. Keep an inventory and a written response. Know which variations you already own, mark them so they never consume attention again, and decide in advance who confirms a finding, who preserves evidence, who contacts the registrar and who decides on a dispute. This item turns the other nine into outcomes.

Mail authentication does a different job

SPF, DKIM and DMARC are worth publishing and enforcing, and they do not solve this problem. SPF lets a domain state which hosts may send mail using its name, DKIM lets a message carry a signature a domain vouches for, and DMARC tells receivers what to do when a message fails those checks, from no action up to rejection. Together they establish that mail claiming to come from your domain really does. A lookalike does not claim to be your domain: it is a different domain, and it can publish valid authentication records of its own.

What authentication buys you is that the cheapest attack, spoofing your exact name, stops working, which pushes an attacker towards a lookalike. That is a real improvement, because a lookalike costs money, leaves a registration record, and is visible to anybody monitoring for it.

The signal to watch on a variation is mail records. A name that merely resolves may be parked. A name configured to send or receive mail has had a deliberate decision made about it.

What monitoring covers that registration cannot

Monitoring changes the question from which names might exist to which names now do. That is a much smaller set, and it is the set that matters, because an unregistered permutation harms nobody.

It also covers patterns nobody thought to buy. The keyword families are effectively unbounded, so no purchasing decision covers them, but a check that resolves candidates across those families reports the ones actually registered. Unit 42’s detector found 13,857 squatting domains registered in December 2019 alone; no portfolio anticipates that stream, but a re-check sees the ones aimed at you.

Timing is the other benefit. A name being prepared for abuse leaves public traces before it is used: a registration record, then frequently a certificate in a transparency log, then mail records or a page. The checker on this site works from those traces without ever connecting to a suspect site, taking its evidence from registry RDAP, DNS over HTTPS, certificate transparency logs and passive urlscan.io search. On the Pro plan a domain is re-checked daily and certificate logs are searched every 30 minutes, so a name seen for the first time reaches the report within the hour. The rules behind every label are on the methodology page.

Build the review process before you need it

The first check on an established brand returns more findings than anyone expected, and the common failure is that the list is read once, found overwhelming, and never read again. A process that survives that moment settles ownership first, keeps a status on every finding that outlives the report, reviews only the difference after the first pass, and tunes alerts so that they are believed. The domain monitoring guide sets those out in detail.

Decide the response before the finding

When a finding is real, the useful decisions are made in advance: who confirms it is not yours, who preserves the evidence, who contacts the registrar or hosting provider, and who decides whether a dispute is worth its cost and delay. A UDRP filing at 1,500 US dollars is cheap beside a phishing campaign against your customers and expensive beside a parked page, and the person deciding should know which they are looking at.

Most findings never reach that stage. The value of writing it down is that the ones which do are handled in hours rather than debated for a week.

What protection does not mean

No combination of registration and monitoring prevents somebody from registering a confusable name. What it does is remove the cheapest routes, make the remaining ones visible early, and ensure that when one is used you find out from your own process rather than from a customer.

Be sceptical of any tool that promises more than that. A check reports what public records returned when it ran. It does not load suspect pages, it does not enumerate every possibility, and it does not decide who is acting in bad faith. Similarity is never proof of intent, and a review priority is an order for human attention rather than a finding of phishing.

Common questions

Should I register misspellings of my domain?
Register a few: the endings your customers assume, the one or two closest keyboard typos, and any name you print on physical material. Redirect them to the real site. Do not try to register every variation, because most registered lookalikes are keyword compounds and alternative endings that no typo list covers, and the list never finishes.
How many typo domains should I register?
For most brands five to ten. A six-letter name generates 3,001 candidates under twenty pattern families, and at Verisign’s wholesale .com price of 10.26 US dollars a year, rising to 10.97 in November 2026, buying all of them would cost over thirty thousand dollars annually while still missing the next keyword. Buy the handful whose loss would hurt and monitor the rest.
Is it illegal to register a typo domain?
Not by itself. In the United States the Anticybersquatting Consumer Protection Act applies when a name confusingly similar to a mark is registered with a bad faith intent to profit, and the UDRP lets a mark owner recover a name registered and used in bad faith. A brand registering typos of its own name is doing the opposite of either.
How do I stop someone typosquatting my domain?
You cannot stop the registration, because registries do not check for resemblance. You can make it useless: publish SPF, DKIM and DMARC so your exact name cannot be spoofed, monitor the candidate space so a new registration is seen within days, and use the registrar’s abuse process, the URS or the UDRP once a name is used in bad faith.
What does the Trademark Clearinghouse do?
It authenticates trademark records and provides them to registries and registrars. A recorded mark gets priority access to matching names during a new ending’s sunrise, and the holder is notified after someone registers a matching name. The notice fires on a match with the recorded mark, so misspellings and compounds are outside it.

Sources and further reading

  1. UK National Cyber Security Centre: Phishing attacks: defending your organisation
  2. ICANN: Trademark Clearinghouse
  3. Trademark Clearinghouse: Claims Notice
  4. ICANN: Uniform Domain-Name Dispute-Resolution Policy (UDRP)
  5. ICANN: Uniform Rapid Suspension System (URS)
  6. ICANN: URS Procedure (PDF)
  7. WIPO: Schedule of fees for UDRP cases
  8. 15 U.S.C. 1125(d): Cyberpiracy prevention (Cornell LII)
  9. RFC 4033: DNS Security Introduction and Requirements
  10. RFC 6797: HTTP Strict Transport Security (HSTS)
  11. RFC 7208: Sender Policy Framework (SPF)
  12. RFC 6376: DomainKeys Identified Mail (DKIM) Signatures
  13. RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
  14. Microsoft Edge: How Edge can protect you from typosquatting
  15. Microsoft Edge policy: TyposquattingCheckerEnabled
  16. Domain Name Wire: Verisign raising wholesale .com prices (2026)
  17. Unit 42: Cybersquatting: attackers mimicking domains of major brands
  18. Public Suffix List
  19. ICANN: Registration Data Access Protocol (RDAP)
  20. Typosquatting.ai: methodology and data sources

Keep reading in Typosquatting