Typosquatting
Typosquatting registers look-alike domains — misspellings or swapped characters — to catch mistyped URLs and lend fake emails and sites credibility.
Typosquatting (also called URL hijacking or domain mimicry) is the practice of registering domain names that closely resemble legitimate ones — gooogle.com, micros0ft.com, company-payroll.com — to capture users who mistype an address or fail to notice the difference. Attackers use these look-alike domains to host credential-harvesting pages, distribute malware, intercept email, and make phishing messages look authentic at a glance.
How it works
Attackers systematically register variations of a target brand's domain: common misspellings (amazom), swapped or doubled letters (paypa1, nettflix), different top-level domains (.co instead of .com), added words (login-microsoft.com), or homoglyphs — characters from other alphabets that render almost identically, such as a Cyrillic "а" replacing a Latin "a". The domain then serves one of several purposes. In mass campaigns, it catches accidental traffic. In targeted attacks — especially business email compromise — the attacker emails a company's finance team from a domain one character away from a real supplier's, and the visual similarity carries the deception. Typosquatted domains are also used against developers, mimicking package registries and code repositories to spread malicious software.
Because the fake domain is real and often has valid HTTPS, the browser padlock offers no protection — the connection is genuinely secure, just secured to the wrong party. A related attack, pharming, removes the typo from the equation entirely: by corrupting DNS resolution it sends users who type the correct address to the attacker's server.
How to defend against it
Defensively register the most obvious variants of your own domains and monitor new registrations that resemble your brand. Enforce DMARC, SPF, and DKIM so attackers cannot spoof your exact domain and are pushed toward detectable look-alikes. For inbound risk, configure email security to flag newly registered and look-alike sender domains, and require out-of-band verification for any payment or banking change regardless of how legitimate the email appears. Train employees to verify domains character by character in high-stakes contexts — and measure whether that habit holds under pressure with realistic phishing simulations that use look-alike domains, the same way real attackers do.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo