Typosquatting.ai
KNOW WHAT LOOKS LIKE YOU

How the Typosquatting Checker Works

Turn a domain name into a clear, evidence-based review list.

by Typosquatting.ai ResearchLast updated 20 September 2026

1. Generate candidate names

Enter a public domain, such as example.com. We normalize it to its registered domain and the discovery engine generates thousands of candidates from about twenty pattern families: missing, repeated, transposed and swapped characters, lookalike and Cyrillic characters, impersonation keywords in several positions, about 180 alternative endings and the same name on public hosting platforms. Every candidate is resolved over DNS; registered and dormant names, plus names found in certificate-transparency logs, become the report.

Normalising first matters more than it sounds. A name has one registrable form, and generating from anything else produces candidates for a domain nobody owns.

  • Characters removed, doubled, transposed, or replaced by a keyboard neighbour.
  • Shapes that read alike, including the rn sequence that resembles m.
  • Impersonation words such as login, secure and support, placed before and after the name.
  • The same label under roughly 180 other endings.
  • The name as a subdomain on common public hosting platforms.

2. Check public records

For the highest-priority findings the checker requests registry registration data through RDAP and queries DNS records for IPv4, IPv6, mail routing, and nameservers. If available, it shows historical website observations from public scans. It does not visit the potentially suspicious website.

SourceWhat it answersWhat it cannot answer
Registry RDAPWho the registrar is, when the name was registered, what the registry will allowWho the registrant is, since contact data is normally redacted
DNS over HTTPSWhere the name points, and whether it can carry mailWhether anything was ever served or sent
Certificate transparency logsThat somebody proved control of the name to a certificate authorityWhat sits behind the certificate
Passive scan historyWhat a public scanner recorded earlier, if it had seen the hostAnything current, because nothing is fetched now

3. Review the evidence

Each finding includes its pattern, registration status, age when disclosed, registrar, DNS information, and an explanation of review priority. An unavailable lookup stays unknown; an error is never treated as an unregistered domain. A check takes one to three minutes and the page updates itself while it runs.

Every row carries the reason it was labelled, and the rule behind the reason is published. If you disagree with a row, you can see exactly which fact produced it.

A lookup that failed is reported as Unknown and never as clean. A provider outage must not be able to make a registered domain look safe.

4. Decide what to investigate

Elevated priority indicates a combination of actionable signals: active infrastructure with a recent registration, or an impersonation keyword on a registration less than a year old. Review means some infrastructure or registration evidence exists. Low signal means no registry record and no DNS name were found. None of these labels guarantees safety or confirms phishing.

Elevated
Look at this first. Active infrastructure on a recent registration, or an impersonation keyword on a young name.
Review
Some registration or infrastructure evidence exists, without the combination that raises it further.
Possibly yours
Matches your own inventory, registrar or nameservers. Confirm internally before treating it as hostile.
Low signal
No registry record and no DNS answer at the moment of the check.
Unknown
The lookup did not complete. It is not a result, and it never counts as a clean one.

What the checker never does

The boundary is deliberate, and it is the reason the evidence holds up. Everything the report contains was read from a public record rather than taken from the other party's server.

  • It never connects to a suspect domain to gather evidence, so a report cannot tell you what a page contains. In the panel, our own screenshot service can render a picture of a home page, for display only.
  • It never submits a form, signs in, or downloads anything.
  • It does not decide intent, ownership or trademark rights.
  • It does not provide legal advice, and a review priority is not a finding of phishing.

What a clean result means

A report with nothing in it is a statement about a set of candidate names at a moment in time. The engine resolves at most the first 2,970 candidates, covers the pattern families it publishes, and cannot enumerate every script, ending or subdomain that exists.

So read an empty report as a reason to move on today, not as proof that nothing resembles your brand. A name registered an hour after the run is invisible until the next one.

No findings is not the same as nothing to find. The methodology page lists exactly which patterns and sources were covered.

What happens to the domain you check

A public check runs as a background job. The job record and the finished report are kept for twenty-four hours so that the results page can show them, and a scheduled sweep then deletes them. Anyone checking the same domain inside that window is served the finished report rather than starting a new run; adding fresh=1 to the results address runs it again.

Those records hold the domain and its findings, never an address or an account. The domain also appears in the page address, so it may be present in your browser history and in ordinary hosting request logs. Reports run from a panel account are kept in that account until you delete them.

Sources and further reading

  1. ICANN: Registration Data Access Protocol (RDAP)
  2. Cloudflare: DNS over HTTPS JSON API
  3. RFC 6962: Certificate Transparency
  4. urlscan.io: API documentation
  5. Public Suffix List
  6. Unicode Technical Standard #39: Unicode Security Mechanisms (confusables)
  7. Typosquatting.ai: methodology and data sources
  8. Typosquatting.ai: privacy policy