Typosquatting
Registering a domain name that closely resembles a legitimate one, relying on typing mistakes or visual similarity to trick visitors.
Definition
Typosquatting is the practice of registering a domain name that is a slight misspelling, alternate extension, or visual variation of a legitimate website's address, with the goal of capturing visitors who make a small typing error or fail to notice the difference. Attackers use these lookalike domains to host phishing pages, distribute malware, or redirect traffic for financial gain.
Common typosquatting techniques include swapping adjacent letters, adding or omitting a single character, substituting similar-looking characters such as a zero for the letter O, or using a different top-level domain such as .co instead of .com. A visitor who mistypes a company's web address, or clicks a lookalike link in a phishing email, lands on a page designed to look identical to the real site, often complete with a fake login form. Some registered typosquat domains sit unused for years, only activated once the attacker is ready to launch a campaign.
Typosquatting is a persistent risk because it does not require compromising the legitimate website at all, only registering a similar name, which makes it cheap and difficult to fully prevent. It is frequently combined with phishing emails and brand impersonation, where the lookalike domain lends false credibility to a fraudulent message referencing a bank, government service, or well known company. Organizations serving Indonesian consumers are targeted with domains that mimic local bank names or common .co.id patterns, since customers may not scrutinize the exact spelling of a familiar brand.
Organizations can proactively register common misspellings and alternate extensions of their own domain, and monitor for newly registered lookalike domains using domain watch services. Employees and customers should be trained to check a web address carefully before entering credentials, ideally by typing known addresses directly or using saved bookmarks rather than following links. Browser security features and DNS filtering that flag or block known typosquatting domains add a technical layer that catches mistakes before they lead to a compromised page.
At a glance
- Severity
- Medium
- Prevalence
- Very common
- Primary targets
- Customers and employees of well-known brands, banks, and government services
- Also known as
- URL hijacking
How it works
- 1
Registration: an attacker registers a domain that is a slight misspelling, alternate extension, or visual variation of a legitimate address.
- 2
Hosting: the lookalike domain hosts a page designed to look identical to the real site, often with a fake login form.
- 3
Traffic capture: visitors arrive by mistyping the address directly or by clicking a lookalike link in a phishing email.
- 4
Deception: because the page mirrors the real one closely, visitors do not notice the difference and enter credentials or payment details.
- 5
Harvest: the attacker captures whatever is entered and may combine it with brand impersonation for added credibility.
Warning signs
- A web address with an extra, missing, or swapped letter compared to what you expected
- A familiar-looking site using an unusual top-level domain, such as .co instead of .com
- A login page reached by clicking a link rather than typing the address directly
- Small visual differences, like a different favicon or slightly off branding
- A site asking for credentials immediately without normal navigation
How to defend
- Type known web addresses directly or use saved bookmarks instead of following links
- Check a web address carefully before entering credentials
- Register common misspellings and alternate extensions of your own organization's domain
- Monitor for newly registered lookalike domains using domain watch services
- Use browser security features and DNS filtering that flag known typosquatting domains
Real-world example
A customer searching for their bank's website mistypes the domain by one letter and lands on a typosquatted page built to look identical to the real login screen. They enter their username and password without noticing the subtle misspelling in the address bar, handing their credentials directly to the attacker.
How Claro helps
Claro's phishing simulations can include typosquatted lookalike domains so employees practice spotting subtle URL differences in a safe, controlled environment.
Frequently asked questions
What is the difference between typosquatting and phishing?
Phishing is the broader deceptive message or attack. Typosquatting is a specific technique of registering a lookalike domain, which is often used to host the fake page a phishing email links to, or to catch typing mistakes directly.
Why is typosquatting hard to fully prevent?
It does not require compromising the legitimate website at all, only registering a similar name, which is cheap and does not depend on any vulnerability in the real site.
How can I spot a typosquatted domain?
Look carefully for swapped or missing letters, substituted characters like a zero for the letter O, and unusual top-level domains such as .co instead of .com, especially before entering any credentials.
Does registering my own domain misspellings help?
Yes. Proactively registering common misspellings and alternate extensions of your organization's domain denies attackers an easy option and reduces the pool of lookalike names available to them.
Related terms
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Clone Phishing
Clone phishing is an attack that copies a real, previously delivered email and resends it with malicious links or attachments swapped in, exploiting the trust the recipient already placed in the original message.
Brand Impersonation
A phishing tactic where attackers mimic a well known company's branding, tone, and communication style to make fraudulent messages appear legitimate.
Quishing (QR Code Phishing)
Quishing is a phishing attack that hides a malicious link inside a QR code to trick people into visiting a fraudulent site or installing malware.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo