Ty­po­squat­ting refers to the de­lib­er­ate re­gis­tra­tion of domains that look almost identical to well-known web addresses and contain only minimal typing errors. The goal is to catch users who mistype a web address and redirect them to fake or mis­lead­ing websites.

How does ty­po­squat­ting work?

Ty­po­squat­ting relies on small changes to a domain name. A letter may be omitted, swapped, or replaced with a visually similar character. Homoglyph attacks are es­pe­cially difficult to spot. In these cases, attackers might use the digit ‘0’ instead of the letter ‘O’ or Unicode char­ac­ters from other alphabets. These vari­ations are barely no­tice­able to the human eye.

Classic examples often involved mis­spelled names of major search engines or online shops. Today, ty­po­squat­ting in­creas­ingly targets SaaS services, cloud platforms, AI tools, and payment providers. Fake login pages that imitate ChatGPT, Microsoft 365, or well-known crypto platforms show how pro­fes­sion­al these attacks have become. The goal is to redirect ac­ci­dent­al traffic and profit from it. In more serious cases, attackers use highly con­vin­cing login pages to steal cre­den­tials or payment in­form­a­tion. For companies, every ty­po­squat­ting incident can mean a potential loss of customers.

Note

Ty­po­squat­ting is often confused with cy­ber­squat­ting, but the intent is different. Rather than blocking or reselling a brand domain, ty­po­squat­ting aims to capture traffic with domain names that differ only slightly from the original.

Common types of ty­po­squat­ting

Criminals use several forms of ty­po­squat­ting to mislead users. These are the most common types:

  • Typos: Trans­posed letters, doubled char­ac­ters, or missing char­ac­ters are among the most common variants. Attackers create domains that differ only slightly from a well-known address. Many major brands now register these versions them­selves and use a redirect to send users to the main domain before the addresses can be misused.
  • Spelling mistakes: Not every incorrect domain comes from typing too quickly. Per­man­ently mis­spelled brand or product names are also de­lib­er­ately re­gistered as a domain. These variants can generate sig­ni­fic­ant traffic, es­pe­cially for popular brands.
  • Al­tern­at­ive spellings: Different spellings of common words can also create op­por­tun­it­ies for ty­po­squat­ting. For example, a business using www.travellerdeals.com may also need to consider whether users might enter www.travelerdeals.com.
  • Hyphen domains: Domains with and without hyphens are es­pe­cially vul­ner­able. Adding or removing a hyphen creates a separate address. Ty­po­squat­ters also combine well-known brands with additions such as ‘shop’, ‘online’, or ‘service’ to suggest an official con­nec­tion.
  • Incorrect domain endings: The large number of new top-level domains has increased the risk further. A brand re­gistered under .com, for example, can also be re­gistered under .shop, .online, or .web. The .co ending is es­pe­cially popular because it closely resembles .com. If you only register one TLD, you risk leaving al­tern­at­ive endings open to mis­lead­ing or fraud­u­lent use.
Variant De­scrip­tion Example Main risk
Classic typo Trans­posed, doubled, or missing letters amazom.co.uk instead of amazon.co.uk Traffic in­ter­cep­tion, re­dir­ec­tion to ad pages
Spelling mistake Per­man­ently mis­spelled brands linkdin.com instead of linkedin.com Deception, data theft
Al­tern­at­ive spelling Different spellings of the same term colourprint.com vs. colorprint.com Customer loss, brand dilution
Hyphen variant Adding or removing hyphens online-bank-login.com Mis­lead­ing login pages
Brand addition Adding trust-building terms delivery-tracking.com Phishing, theft of personal data
Different TLD Same name with a different ending company-support.co instead of company-support.com Login abuse
Homoglyph attack Re­place­ment with visually similar char­ac­ters rnicrosoft.com (rn instead of m) Hard-to-detect phishing
IDN/Unicode abuse Use of foreign alphabet char­ac­ters with an identical ap­pear­ance аррle.com (Cyrillic char­ac­ters) Highly pro­fes­sion­al scam sites

Ty­po­squat­ting in SaaS and AI en­vir­on­ments

Ty­po­squat­ting has become much more pro­fes­sion­al in recent years. Instead of relying on simple ad redirects, attackers now focus on high-value accounts and sensitive login details. Cloud services, project man­age­ment tools, payment platforms, and AI ap­plic­a­tions with paid sub­scrip­tions are es­pe­cially at­tract­ive targets.

Attackers register domains that look almost identical to official login pages. They combine common typos with trust-building terms such as ‘secure’, ‘verify’, or ‘account’ and often use valid TLS cer­ti­fic­ates. This can make the page look le­git­im­ate at first glance.

Typical scenarios include:

  • Fake login portals for project man­age­ment or col­lab­or­a­tion tools
  • Fake invoice pages from parcel delivery services
  • Imitated payment or wallet portals
  • Imitated AI platforms with supposed upgrade notices
  • Domains with minimal character changes, such as 1 instead of l or 0 instead of O

AI-supported website gen­er­a­tion makes it easier to create con­vin­cing copies of real provider websites in a very short time. As a result, ty­po­squat­ting is no longer just a way to capture ac­ci­dent­al traffic. It has become a key part of modern phishing strategies and creates concrete risks for companies:

  • Loss of potential customers
  • Damage to brand image and repu­ta­tion
  • Increased support and security costs
  • Possible data exposure due to com­prom­ised login cre­den­tials

Ty­po­squat­ting is not auto­mat­ic­ally illegal in the United Kingdom. However, re­gis­ter­ing and using typo domains can violate trademark rights, amount to passing off, or qualify as an abusive domain re­gis­tra­tion. The key question is usually whether the domain creates confusion, exploits another company’s repu­ta­tion, or was re­gistered in bad faith.

Trademark law

Trademark law is one of the main legal bases used against ty­po­squat­ting in the UK. If a typo domain is con­fus­ingly similar to a re­gistered trademark and is likely to mislead users, this may con­sti­tute trademark in­fringe­ment.

Possible actions may include:

  • Demanding that the domain holder stop using the domain
  • Seeking transfer or can­cel­la­tion of the domain
  • Claiming damages or in­junct­ive relief in certain cases

Cases are par­tic­u­larly clear when the typo domain is used for competing goods or services, phishing, or mis­lead­ing com­mer­cial activity.

Passing off

Even without a re­gistered trademark, busi­nesses in the UK may rely on the legal concept of passing off. This applies when someone uses a domain name in a way that misleads users into believing there is a con­nec­tion with another business or brand.

To succeed in a passing off claim, a business generally has to show:

  • goodwill or repu­ta­tion in the name or brand,
  • a mis­lead­ing rep­res­ent­a­tion by the domain holder, and
  • resulting damage or likely damage.

Domain dispute pro­ced­ures

For .uk domains, disputes are commonly handled through the Nominet Dispute Res­ol­u­tion Service (DRS) rather than through court pro­ceed­ings. The DRS applies when a domain is con­sidered an ‘abusive re­gis­tra­tion’.

A com­plain­ant generally has to show that:

  • they have rights in a name or trademark similar to the domain,
  • the domain re­gis­tra­tion took unfair advantage of those rights or harmed them, and
  • the re­gis­tra­tion or use was abusive or made in bad faith.

The DRS can lead to the transfer or can­cel­la­tion of the domain.

In­ter­na­tion­al dispute res­ol­u­tion

Many in­ter­na­tion­al domains such as .com domains may also be chal­lenged through the Uniform Domain-Name Dispute-Res­ol­u­tion Policy (UDRP), often ad­min­istered by WIPO.

Criminal relevance

If typo domains are used for phishing, payment fraud, malware dis­tri­bu­tion, or cre­den­tial theft, criminal laws may also apply. Depending on the conduct involved, this can include fraud offences or offences under computer misuse le­gis­la­tion.

Ty­po­squat­ting from a business and private user per­spect­ive

Ty­po­squat­ting can affect both busi­nesses and private in­di­vidu­als, but the risks are not the same.

Per­spect­ive Risk Typical con­sequences Pro­tec­tion approach
Busi­nesses Brand abuse, traffic loss, phishing under their own name Loss of revenue, repu­ta­tion­al damage, higher support and security costs Domain strategy, mon­it­or­ing, trademark re­gis­tra­tion, technical safe­guards
Private in­di­vidu­als Entering login cre­den­tials on fake sites Account takeover, identity theft, financial loss Checking URLs, password manager, two-factor au­then­tic­a­tion

Busi­nesses usually need to respond with a com­bin­a­tion of strategic, technical, and legal measures. For private users, the focus is more on everyday caution and basic security practices. In both cases, ty­po­squat­ting is not just a the­or­et­ic­al risk, but a practical security issue in everyday digital life.

How to protect yourself against ty­po­squat­ting

You cannot prevent ty­po­squat­ting com­pletely. However, you can reduce the risk sig­ni­fic­antly by combining a clear domain strategy with technical safe­guards and internal processes.

  • Register common spelling variants early: Secure common typos, al­tern­at­ive spellings, relevant hy­phen­ated versions, and important domain ex­ten­sions for your brand. Fre­quently used typo domains can redirect to your main domain to prevent misuse.
  • Reserve important domain ex­ten­sions: In addition to your primary domain, register key ex­ten­sions such as .com, .net, .org, or industry-specific TLDs like .shop, .store, or .online. This reduces the risk of third parties using your brand under al­tern­at­ive ex­ten­sions.
  • Use domain mon­it­or­ing: Use mon­it­or­ing services that scan newly re­gistered domains for names similar to your brand. Early alerts help you respond before harmful content spreads.
  • Protect your brand through trademark re­gis­tra­tion: Register your trademark na­tion­ally or in­ter­na­tion­ally. A re­gistered trademark makes it much easier to enforce your rights, for example through a UDRP pro­ceed­ing or legal action.
  • Strengthen DNS and email security: Add technical safe­guards that make your domain in­fra­struc­ture harder to abuse. These include DNSSEC to secure name res­ol­u­tion, as well as SPF, DKIM, and DMARC to help prevent email spoofing.
  • Raise awareness among employees and customers: Train employees to recognise sus­pi­cious links and login pages. Also make it clear to customers which official domains and com­mu­nic­a­tion channels you use.
  • Act quickly and consider legal action: If you discover an abusive domain, document its content and assess potential trademark or unfair com­pet­i­tion claims. The faster you respond, the lower the risk of repu­ta­tion­al damage, data misuse, or customer loss.

How to recognise a ty­po­squat­ting site

Ty­po­squat­ting sites are often pro­fes­sion­ally designed and tech­nic­ally con­vin­cing. Even so, there are common warning signs that can point to a ma­nip­u­lated or fake domain:

  • Check the URL carefully: Look at the web address character by character. Pay attention to swapped letters, extra char­ac­ters, missing letters, or lookalike com­bin­a­tions such as ‘rn’ instead of ‘m’ or ‘0’ instead of ‘O’.
  • Watch for unusual domain ex­ten­sions: Be cautious if a well-known brand suddenly appears under an un­fa­mil­i­ar extension such as .co, .online, or .shop.
  • Look for sus­pi­cious additions in the domain: Terms such as ‘secure’, ‘verify’, ‘login’, or ‘support’ combined with a brand name are common in phishing domains.
  • Be wary of login pages without context: If you land directly on a login page without actively re­quest­ing it, check the URL es­pe­cially carefully.
  • Pay attention to unusual redirects: Multiple automatic redirects or a URL that changes after the page loads can indicate ma­nip­u­la­tion.
  • Do not rely on the cer­ti­fic­ate alone: A valid TLS cer­ti­fic­ate (https) only shows that the con­nec­tion is encrypted. It does not prove that the site is le­git­im­ate.
  • Check for spelling or layout errors: Many phishing sites now look pro­fes­sion­al, but faulty text or in­con­sist­ent design can still be a warning sign.

Technical tools such as password managers add another layer of pro­tec­tion. They usually auto-fill login details only on the exact domain you have saved, which can help alert you to typo domains created through ty­po­squat­ting.

Domain Transfer
Transfer your domain, hassle free
  • Zero downtime
  • Free SSL & email
  • £0 transfer fee, plus great offers

Reviewers

Go to Main Menu