Typosquatting.ai
THE BASICS

What Is Typosquatting? Meaning, Cases and Is It Illegal

A single changed letter is enough to send someone to a website that the brand on the label does not control.

by Andrew Maged16 September 2026updated 23 September 202612 min read

Typosquatting, also called URL hijacking, is the registration of domain names that closely resemble an existing name, so that people who mistype an address, misread a link, or trust a familiar-looking brand arrive somewhere the brand does not control.

This guide covers what the term means, what typosquatted domains are used for, documented cases, how typosquatting differs from cybersquatting, whether it is illegal, how individuals protect themselves, and what a public check can and cannot establish.

What does typosquatting mean?

Typosquatting, also called URL hijacking, is the registration of a domain name built to be confused with another one. The classic case is a typing mistake: someone means to visit a familiar site, misses a letter, and the name they land on has already been registered by somebody else. The practice survives because it needs no vulnerability. A domain costs a few pounds, registration asks nobody to prove a relationship to the brand in the name, and the mistake it exploits is made by people rather than software.

The term is used more broadly now than its literal meaning suggests. In practice it covers any registration whose resemblance to a real name is the point: missing or doubled letters, characters that look alike in an address bar, a brand name with a word such as login or support attached, and the same name under a different ending. Few people reach these names by typing; most arrive through a link in a message, a search advertisement, a QR code, or an automated client that follows a name exactly.

Typosquatting describes the registration, not the intent behind it. Some of these names are registered by the brand itself, defensively. Telling the cases apart is a question of evidence, which is why any label attached to a name should come with the rule that produced it.

What is a typosquatted domain used for?

The name is only the delivery mechanism. Palo Alto Networks’ Unit 42 counted 13,857 squatting domains registered in December 2019 alone, an average of 450 a day, and classified 18.59 percent of them as malicious. That leaves a large majority doing something other than phishing.

Phishing
The page imitates a login or payment form for the brand in the name. One captured credential can be worth many times the registration cost.
Malware
The page pushes a download or exploits the browser on arrival. The best known example is goggle.com, which McAfee featured in a 2006 web safety promotion because of the malware that visiting it installed at the time.
Advertising and parking
The name shows a page of links and earns a fraction of a penny per click. It is the commonest use by far, because it needs no content and no interaction with the visitor.
Affiliate redirection
The visitor is forwarded to the real site through an affiliate link, so the registrant earns commission on a sale the brand would have made anyway.
Resale
The name is held so that the brand will eventually pay for it, the pattern the dispute policies were written for.
Criticism and satire
In 2016 the comedian John Oliver registered equifacks.com, experianne.com and tramsonion.com for a segment about the credit bureaus, and a criticism site at fallwell.com survived a cybersquatting claim in a US appeals court.

Which patterns do these registrations follow?

The permutations are mechanical: a character dropped, doubled, swapped or replaced by its keyboard neighbour, a lookalike character from another script, a keyword such as login attached, or the same name under a different ending. From about twenty pattern families a six-letter name yields thousands of candidates, and the families that dominate are not typing mistakes but the brand combined with a keyword or placed under another ending.

The examples guide in this cluster works through all twenty families with an example of each, the candidate count for example.com, and what a registered name in each family usually means.

Notable typosquatting cases

Each case below can be checked against a court record, a panel decision or a published investigation.

Nicole Kidman v. Zuccarini, 2001
A WIPO panel ordered nicholekidman.com transferred to the actress, noting that the only difference from her name was a purposeful misspelling created by the addition of an h. The name had pointed at advertisements for sexually explicit sites.
Lamparello v. Falwell, 2005
Christopher Lamparello registered fallwell.com in 1999 for a site criticising the evangelist’s views. The Fourth Circuit held that a gripe site criticising the markholder does not constitute cybersquatting, and in April 2006 the US Supreme Court declined to review the decision.
goggle.com, 2006
A typo of google.com that McAfee used in a web safety promotion because visiting it triggered drive-by malware downloads, including a rogue anti-spyware program known as SpySheriff.
Dell, 2007
Dell filed a case in the US District Court for Southern Florida alleging that firms trading in web addresses had registered and profited from 1,100 domain names confusingly similar to its trademarks through the practice known as domain tasting.

Is typosquatting the same as cybersquatting?

They overlap and are often used interchangeably, but they describe different things. Cybersquatting is registering a name in bad faith because someone else has a right to it, usually a trademark, to sell it, divert its traffic, or keep its owner from using it. It is a legal characterisation, and it is the ground on which a dispute under the Uniform Domain-Name Dispute-Resolution Policy is argued.

Typosquatting is a description of the name itself: it resembles another one closely enough to be confused with it. A typosquatted domain is frequently also cybersquatting, but not always: a name can resemble a brand without infringing any right, and a name can infringe a trademark without resembling it in spelling. The distinction matters when you decide what to do. A dispute is a legal process with a standard of proof about intent; an abuse report to a registrar is an operational process about what a page is doing now.

Is typosquatting illegal?

Registering a confusable name is not, by itself, an offence anywhere. What the law addresses is what the name is for and whose rights it trades on. Three routes matter in practice, and each turns on intent or an infringed right rather than on the resemblance alone.

In the United States the Anticybersquatting Consumer Protection Act, at 15 U.S.C. 1125(d), creates civil liability for a person who has a bad faith intent to profit from a mark and registers, traffics in or uses a domain name that is identical or confusingly similar to it. A misspelling is confusingly similar on its face. The mark owner may elect statutory damages of not less than 1,000 and not more than 100,000 US dollars per domain name, as the court considers just. Bad faith is the hinge: the Falwell case failed because a criticism site with no commercial purpose showed no intent to profit.

The Uniform Domain-Name Dispute-Resolution Policy is not a law but a contract term. Every registrar of a generic top-level domain must follow it, and it lets disputes arising from abusive registrations, cybersquatting among them, be decided in an expedited administrative proceeding rather than a court. The complainant must show confusing similarity to its mark, no legitimate interest on the registrant’s side, and bad faith registration and use. The remedy is transfer or cancellation, never damages. WIPO’s fee for a single-panellist case covering one to five names is 1,500 US dollars, and the cost of doing this at scale is visible in Lego’s reported 500,000 US dollars across 309 UDRP cases.

The Uniform Rapid Suspension System complements the UDRP for newer generic endings with a lower-cost, faster path for the most clear-cut cases. The burden of proof is clear and convincing evidence, and the remedy is narrower: the registry suspends the name for the balance of its registration period rather than transferring it.

Elsewhere the same conduct is generally pursued as trademark infringement or passing off under national law. In every route the resemblance is the starting point and never the whole case, which is why a detection report should describe what a name carries and leave the word illegal to the people who can prove intent.

Is a lookalike domain always an attack?

No, and treating every one as an attack exhausts the people doing the reviewing. A registered variation of your domain has several ordinary explanations.

  • You registered it. Defensive registrations are common and are frequently forgotten between the team that bought them and the team reviewing findings.
  • An unrelated business holds the name legitimately. Short words and abbreviations collide constantly across industries and countries.
  • It is parked, monetised by advertising on a registrar’s holding page, with no interest in any particular brand.
  • It was registered speculatively for resale, which may be cybersquatting but is not phishing.
  • It is genuinely staged for abuse, with a certificate issued, mail records configured, or a page already imitating a login screen.

What separates the two in the public record?

You cannot tell these cases apart from the name. You can tell them apart from the public records, and four sources carry most of the weight.

Registration data through RDAP gives the creation date and, where the registry discloses it, the registrar. Age is the single most useful field in the record, which is why a keyword pattern registered under a year ago belongs at the top of any review queue. DNS answers show whether anything is running: an address record means a host is reachable, and mail records mean a considered decision has been made. Certificate transparency logs frequently move first, because a certificate is issued when someone prepares to serve a page, often days before it appears. Passive scanning services record what a host looked like when somebody else visited it.

How to protect yourself from typosquatting

Most guidance on this subject is written for brand owners. The individual side is shorter, and it works because it removes the moment where a person judges an address by eye.

  • Reach important sites from a bookmark or an address you have typed before, not from a link in a message that is asking you to act.
  • Let a password manager do the matching. It fills a saved login only on the exact domain it was saved for, so a login form on a lookalike stays empty.
  • Read the address from the right. The label immediately before the ending is the registration; everything to its left was chosen by whoever holds it.
  • Turn on the browser’s own warning where one exists. Microsoft Edge ships Website Typo Protection, on by default, which warns when it appears you have mistyped a popular domain name.
  • If you typed a password into a page you now doubt, change it from the real site and report the address through the service’s own channel.

How do you check a domain for typosquatting?

Start from the registrable form of the name, because that is what a registration covers. For www.shop.example.co.uk the registrable domain is example.co.uk, and the Public Suffix List is what makes that determination reliable across endings such as co.uk.

Generate candidates mechanically, from every family and every common ending, and resolve each one over DNS so the report contains names that exist rather than names that could. Then look up the ones that resolved: registry record, DNS records and a passive web search for the highest-priority rows, with the rest keeping the evidence that found them and saying so.

The checker on this site does this for a domain you own, without an account. Candidates come from about twenty pattern families across roughly 180 endings; evidence comes from registry RDAP, DNS over HTTPS, certificate transparency logs and passive urlscan.io search; it never connects to a suspect site. For example.com it generates 3,001 candidates and resolves the first 2,970. Every rule behind every label is on the methodology page.

What a check cannot tell you

A check reports what public registries and DNS returned at the moment it ran. It does not load the suspect website, so it cannot say what a page contains. It does not enumerate every script, ending or subdomain, so an empty result is not a statement that a brand is safe. A registry that returns no record has only declined to answer.

Most importantly, similarity is not intent. A name that looks like yours, resolves to a host and carries a certificate is a name to review, not a finding of phishing. Review priority is a documented heuristic for ordering human attention, published in full so that nobody has to take a score on trust.

Common questions

Is typosquatting illegal?
Registering a confusable name is not an offence in itself. It becomes actionable when done with a bad faith intent to profit from someone else’s mark, the test in the US Anticybersquatting Consumer Protection Act, or when a UDRP panel finds an abusive registration. Intent and the rights involved decide it, not the resemblance.
What is the difference between typosquatting and cybersquatting?
Typosquatting describes the name: it resembles another closely enough to be confused with it. Cybersquatting describes the conduct: registering a name in bad faith because someone else has a right to it. Many typosquatted names are also cybersquatting; a criticism site or a brand’s own defensive registration is not.
What is an example of typosquatting?
goggle.com, a one-letter typo of google.com, was featured by McAfee in a 2006 web safety promotion because visiting it installed malware at the time. nicholekidman.com, with an added h, was transferred to the actress by a WIPO panel in 2001.
What is URL hijacking?
URL hijacking is another name for typosquatting: registering a name that resembles an existing one so that mistyped or misread addresses arrive somewhere the real brand does not control.
Can I sue a typosquatter?
In the United States a mark owner can sue under the ACPA and elect statutory damages of between 1,000 and 100,000 US dollars per domain name. A UDRP complaint costs 1,500 US dollars for up to five names before a single panellist, but its only remedy is transfer or cancellation.

Sources and further reading

  1. Wikipedia: Typosquatting
  2. 15 U.S.C. 1125(d): Cyberpiracy prevention (Cornell LII)
  3. 15 U.S.C. 1117(d): Statutory damages for cyberpiracy (Cornell LII)
  4. ICANN: Uniform Domain-Name Dispute-Resolution Policy (UDRP)
  5. ICANN: Uniform Rapid Suspension System (URS)
  6. ICANN: URS Procedure (PDF)
  7. WIPO: Schedule of fees for UDRP cases
  8. WIPO decision D2000-1415: Nicole Kidman v. John Zuccarini
  9. Lamparello v. Falwell, 420 F.3d 309 (4th Cir. 2005), FindLaw
  10. The Register: Dell sits on cybersquatters (2007)
  11. Unit 42: Cybersquatting: attackers mimicking domains of major brands
  12. Microsoft Edge: How Edge can protect you from typosquatting
  13. Microsoft Edge policy: TyposquattingCheckerEnabled
  14. UK National Cyber Security Centre: Phishing attacks: defending your organisation
  15. Unicode Technical Standard #39: Unicode Security Mechanisms (confusables)
  16. Public Suffix List
  17. ICANN: Registration Data Access Protocol (RDAP)
  18. Typosquatting.ai: methodology and data sources

Keep reading in Typosquatting