Skip to main content
Network & InfrastructureUpdated September 3, 2026

Typosquatting

Typosquatting (also called URL hijacking) registers domains that are slight misspellings of legitimate websites to capture traffic from users who make typing errors. These domains are often used for phishing, malware distribution, or ad fraud.

Typosquatting is the registration of a domain that a user could type by mistake when aiming for another: a dropped letter, a doubled one, two swapped, a neighbouring key, a different top-level domain. The registrant is betting on traffic that arrives by error and on the user not noticing the address bar.

The same technique serves phishing from the other direction. A look-alike domain in an e-mail (the company name with an extra letter, or a hyphen inserted) passes a glance and hosts a credential page that copies the original. Here the typo is chosen by the attacker rather than made by the victim.

URL hijacking versus typosquatting: the two terms are often used as synonyms, and typosquatting is one form of URL hijacking. The wider term also covers homoglyph domains that use look-alike Unicode characters, combosquatting that appends a plausible word (brand-login, brand-support), and expired-domain takeovers where a real address changes hands. Typosquatting is specifically the misspelling case.

Example

Over one weekend, twelve domains are registered that differ from a bank’s name by one character. All twelve use the same registrar, the same nameservers and resolve to one address. Two already serve a login page. The batch is one campaign, detectable from the registration data alone.

In isMalicious

A domain report on isMalicious shows the registration date, registrar and nameservers that make a batch visible, and the newly registered domain feed at /data/nrd-list is where look-alikes appear first, usually days before the first phishing e-mail is sent.

Frequently Asked Questions

What is Typosquatting?

Typosquatting (also called URL hijacking) registers domains that are slight misspellings of legitimate websites to capture traffic from users who make typing errors. These domains are often used for phishing, malware distribution, or ad fraud.

How is Typosquatting related to Phishing?

Typosquatting and Phishing are both key concepts in threat intelligence. Phishing is a social engineering attack that tricks users into revealing credentials, clicking malicious links, or downloading malware — typically via email. Spear phishing targets specific individuals; smishing uses SMS; vishing uses voice calls.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary