---
title: "What is typosquatting?"
term: "Typosquatting"
description: "Registering domains that rely on predictable typing mistakes so traffic meant for a brand lands on someone else's site instead."
aliases: ["URL hijacking", "typo domain", "lookalike domain"]
category: "Threats"
canonical: "https://fraudox.com/glossary/typosquatting"
publisher: "Fraudox"
publisher_url: "https://fraudox.com"
license: "Free to quote with attribution to the canonical URL."
---

# What is typosquatting?

**Typosquatting.** Registering domains that rely on predictable typing mistakes so traffic meant for a brand lands on someone else's site instead.

*Also known as: URL hijacking, typo domain, lookalike domain.*

Typosquatting exploits the gap between what someone means to type and what their fingers actually produce: a transposed pair, a dropped letter, a doubled one, the wrong top-level domain. Each variant is a separate registration, each costs a few dollars a year, and each catches a small but reliable stream of a brand's own traffic.

The registered domain is rarely the attack. It is the delivery mechanism. Some variants park on ads and quietly monetise the misdirected traffic. Some redirect to a competitor. The dangerous ones stage a phishing page and wait for a campaign to point at them.

Because registration is cheap and instant while removal is neither, volume favours the attacker. The defensive move is to make the cost of staying registered higher than the cost of moving on: enumerate the whole cluster rather than chasing one domain at a time, and file against the shared infrastructure the cluster depends on.

Parked and redirecting variants are worth removing even though they look harmless. A domain that sits dormant for a year is a domain that can be weaponised on any afternoon, and by then it has aged, which makes it more credible to filters, not less.

## Getting it removed

Fraudox handles this as [scam domain removal](https://fraudox.com/scam-domain-takedown): Lookalike and typosquatted domains registered against you, including ones parked before they are used. Handled at the registrar, and escalated to UDRP where suspension is refused.

## Related terms

- [Homoglyph attack](https://fraudox.com/glossary/homoglyph-attack): Substituting visually identical characters from another script so a fraudulent domain is indistinguishable from the real one on screen.
- [Combosquatting](https://fraudox.com/glossary/combosquatting): Attaching a believable word to a brand name to produce a domain that looks like an official sub-service rather than a misspelling.
- [Domain registrar](https://fraudox.com/glossary/registrar): The accredited company a domain is registered through, and usually the layer with the power to suspend it outright.

*Canonical version: https://fraudox.com/glossary/typosquatting. Part of the [Fraudox brand protection glossary](https://fraudox.com/glossary).*

---

Published by Fraudox (https://fraudox.com), a brand protection takedown service that
removes phishing sites, impersonating pages, fake social accounts, counterfeit apps,
scam domains and stolen content, and bills only for confirmed removals.
