This image of a spooky haunted house illustrates our topic about typosquatting.

Domain typosquatting: Protect yourself from typos

Key Takeaway:

A single typo can send your customers straight into a scammer’s hands, so let’s protect your domain against typosquatting.

In 2018, browsers landed on scam sites like itunes.cm and espn.cm 12 million times, just because someone left out a letter. In 2016, Netflix and Citibank customers ran into the same problem with .om typos. A single missing character sent them straight to attackers.

This is typosquatting, and it’s more dangerous than it looks. Here’s how it works, why it matters for your brand, and what you can do about it. You can also get a domain portfolio analysis to see if someone’s typosquatting your brand right here.

This image of a the door to a spooky haunted house illustrates our topic about typosquatting.

What is typosquatting?

Typosquatting means registering domains that look almost identical to well-known web addresses. Scammers rely on typos, misspellings, or the wrong domain ending to redirect traffic their way. Type itunes.cm instead of itunes.com and you land on a fraudster’s site without even noticing.

Typosquatting is also called URL hijacking or brandjacking. It depends entirely on human error. Type a domain name wrong and don’t catch the mistake, and you end up somewhere you never intended. The traffic that should have gone to the real brand goes to the scammer instead.

The first major typosquatting case hit international headlines in 2006, targeting Google. Fraudsters registered foogle.com, hoogle.com, and voogle.com, banking on the fact that F, H, and V all sit right next to G on a keyboard. Companies like Apple and Google have since fought back by registering their own common typo domains and using ICANN services built for this exact problem.

Common types of typosquatting

Typosquatting takes several forms. The examples below are fictional, but the patterns are real.

Simple typos happen constantly, especially for people who type fast or lean on autocorrect. Apple.com can easily become aple.com or appöe.com.

Misspellings come from genuine confusion rather than carelessness. Someone unsure how Apple is spelled might type appel.com. The same logic explains salando.com instead of zalando.com, or addidas.com instead of adidas.com.

Wrong domain extensions are becoming more common as new top-level domains keep appearing. Apple.online or apple.live could pass for the real thing. The most frequent version swaps .com for .co, catching anyone who forgets the last letter.

Alternative spellings also trip people up, especially across languages. Photografie.com instead of fotografie.com is a good example.

Hyphenated domains work by adding or removing a hyphen. During Germany’s 2013 election, visitors typing angelamerkel.de without the hyphen briefly landed on a rival party’s site instead of the chancellor’s own.

Supplemented brand domains attach extra words to a real brand name. Apple-onlineshop.com sounds legitimate but has nothing to do with Apple. Sites like this usually push ads or malware.

Prepended www errors happen when someone types wwwapple.com without the dot. It looks like a small slip, but it’s enough to send traffic somewhere it shouldn’t go.

Why typosquatting is dangerous

Nobody registers a typo domain by accident. These sites exist to make money, usually at someone else’s expense.

Users risk exposure to malware, as seen in the 2006 Google case, where visitors were served malicious downloads. Brand owners lose traffic, revenue, and often their reputation along with it.

Typosquatters generally pursue one of a few goals. Phishing sites collect personal data, from email addresses to credit card numbers, often through a near-perfect copy of the real website. Domain parking involves buying up typo domains purely to resell them to the brand owner at a steep markup. Product counterfeiting uses a convincing fake site to sell knockoff goods. Traffic tapping simply borrows a recognizable name to promote unrelated products or offers.

This image of a shadowy figure at the end of a hallway in a spooky haunted house illustrates our topic about typosquatting.

Typosquatting vs. cybersquatting: what’s the difference?

The two terms get used interchangeably, but they’re not the same. Typosquatting relies on spelling errors and typos. Cybersquatting is broader: it covers registering or using a domain name you have no legal right to, typo or not.

What is cybersquatting?

Cybersquatting means registering domains containing protected terms, brand names, product names, company names, or even the names of well-known people, without any legitimate claim to them.

Cybersquatters typically try to sell these domains back to the rightful owner at inflated prices. Since registering a domain costs almost nothing, and companies are often willing to pay thousands to get it back, the incentive is obvious.

Where the term “cybersquatting” comes from

“Squatter” dates back to 1788, describing someone occupying property they had no right to and paying no rent. The internet version follows the same idea: someone holding a domain they have no legitimate claim to.

One of the earliest legal cases was Avery Dennison Corporation v. Jerry Sumpton in 1998. Sumpton had registered avery.net and dennison.net, matching Avery Dennison’s own brands, along with roughly 12,000 other domains. The judge described the defendants plainly: they weren’t using the domains themselves, only holding them to block the real trademark owners and profit by selling them back at inflated prices.

Real-world typosquatting and cybersquatting cases

Pinterest took action against a Chinese cybersquatter who had registered pinterests.com and pinterest.de, copying Pinterest’s logo and running the sites purely as ad space. Pinterest won, though enforcement in China remains harder than in the US.

Donald Trump faced a different version of the problem in 2007, when a company called Web-Adviso registered TrumpIndia, TrumpBeijing, TrumpAbuDhabi, and TrumpMumbai after the Trump Organization announced hotel plans in India. The sites hosted parody content. A WIPO panel ordered Web-Adviso to pay $32,000 and hand over all four domains, ruling that combining a brand name with a location was still a clear infringement.

The real cost of these infringements

FairWind Partners’ 2016 report, “Cyber Monday 2016: Typosquatting – A Threat to Brands and Consumers,” put the value of traffic diverted to typo domains at over $50 million. That figure doesn’t even count the damage to reputation or customer trust, which is much harder to measure.

Nearly a third of all cybersquatting cases involve banking, fashion, or IT and internet companies. New extensions like .STORE, .SITE, and .ONLINE now account for over 12% of disputes. In 2017, the US led the world in WIPO cases by a wide margin, filing 920 complaints, ahead of France, the UK, Germany, and Switzerland.

This image of someone illuminating a spooky haunted house with a flashlight illustrates our topic about typosquatting.

How us internet users can prevent typosquatting

We can also do plenty ourselves, as normal internet users, to minimize the impact of typosquatting. The safest habit is to search for a site rather than typing the URL straight into your browser. Once you’ve confirmed you’re on the real site, bookmark it and use that bookmark going forward instead of typing the address again. If you’re worried about typos in general, voice commands can help you skip the keyboard altogether.

Beyond that, treat links with some caution. Avoid clicking anything from a source you don’t fully trust, and don’t open attachments that look even slightly suspicious. Keeping antivirus software running in the background adds one more layer of protection if a typo does slip through.

How brands can prevent typosquatting

Register the obvious typo variations of your own domain and redirect them to the correct site. Pick up other relevant extensions beyond your country code, including .com, .shop, or .web. Register alternative spellings and both hyphenated and non-hyphenated versions of your domain. Add anti-spoofing technology and secure email gateways. Warn customers about phishing risks and verify your official social media accounts publicly. Secure your site with SSL, and add trust signals that reassure visitors they’re in the right place.

Registering with the Trademark Clearinghouse and using ICANN’s Trademark Registry Exchange service blocks unauthorized registrations during and after the sunrise period. Adding your brand to Donuts’ Domains Protected Marks List extends that protection across more than 200 new TLDs.

How EBRAND helps protect your brand from typosquatting

EBRAND handles trademark registration with ICANN and enrollment in TREx and DPML. Our domain monitoring tool tracks over 1,000 top-level domains worldwide, flagging violations as they happen so we can assess them and pursue legal action when needed. We also help brand owners build typosquatter-resistant domain portfolios and register the domains that matter most. Learn more about how domain monitoring can help your business right here.

Want to turn insights into actions?

Reach out to the team, and get the conversation started

Want to see
how it works?

Get a free demo of the platform for your organization. See what threats are out there, and how our tools can tackle them.

EBRAND badge

Client login

Welcome to the client login portal, where EBRAND users access their solution platforms. Select your solution below:

Not an EBRAND client yet? Sign up
Discover more on our Solutions pages