Typosquatting
Typosquatting (also called URL hijacking) registers domains that are slight misspellings of legitimate websites to capture traffic from users who make typing errors. These domains are often used for phishing, malware distribution, or ad fraud.
Typosquatting is the registration of a domain that a user could type by mistake when aiming for another: a dropped letter, a doubled one, two swapped, a neighbouring key, a different top-level domain. The registrant is betting on traffic that arrives by error and on the user not noticing the address bar.
The same technique serves phishing from the other direction. A look-alike domain in an e-mail (the company name with an extra letter, or a hyphen inserted) passes a glance and hosts a credential page that copies the original. Here the typo is chosen by the attacker rather than made by the victim.
URL hijacking versus typosquatting: the two terms are often used as synonyms, and typosquatting is one form of URL hijacking. The wider term also covers homoglyph domains that use look-alike Unicode characters, combosquatting that appends a plausible word (brand-login, brand-support), and expired-domain takeovers where a real address changes hands. Typosquatting is specifically the misspelling case.
Example
Over one weekend, twelve domains are registered that differ from a bank’s name by one character. All twelve use the same registrar, the same nameservers and resolve to one address. Two already serve a login page. The batch is one campaign, detectable from the registration data alone.
In isMalicious
A domain report on isMalicious shows the registration date, registrar and nameservers that make a batch visible, and the newly registered domain feed at /data/nrd-list is where look-alikes appear first, usually days before the first phishing e-mail is sent.
Frequently Asked Questions
What is Typosquatting?
Typosquatting (also called URL hijacking) registers domains that are slight misspellings of legitimate websites to capture traffic from users who make typing errors. These domains are often used for phishing, malware distribution, or ad fraud.
How is Typosquatting related to Phishing?
Typosquatting and Phishing are both key concepts in threat intelligence. Phishing is a social engineering attack that tricks users into revealing credentials, clicking malicious links, or downloading malware — typically via email. Spear phishing targets specific individuals; smishing uses SMS; vishing uses voice calls.
Related Terms
Phishing
Phishing is a social engineering attack that tricks users into revealing credentials, clicking malicious links, or downloading malware — typically via email. Spear phishing targets specific individuals; smishing uses SMS; vishing uses voice calls.
NRD (Newly Registered Domain)
A Newly Registered Domain is a domain registered within the past 30–90 days. NRDs are a key risk signal because the vast majority of phishing campaigns, malware distribution, and spam infrastructure uses freshly registered domains to evade blocklists.
Domain Reputation
Domain reputation is a classification of a domain based on its history of malicious activity, registration patterns, and content. Factors include age, registrar, phishing/malware associations, WHOIS data, and appearance on threat feeds.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.