Typosquatting is the registration of domains that closely resemble legitimate ones, through misspellings, character swaps or different extensions, to deceive people into trusting fraudulent websites and emails.
Key facts
- It is the infrastructure behind much phishing and business email compromise: the lookalike sender that carries the fraud.
- DMARC does not stop it, because the attacker owns the lookalike domain and can authenticate it perfectly.
- Techniques include misspellings (goggle.com), homoglyphs (visually similar characters), and alternate TLDs (company.co vs company.com).
The techniques
| Technique | Example | How it works |
|---|---|---|
| Misspelling | goggle.com for google.com | Relies on fast reading |
| Homoglyphs | rnicrosoft.com (rn for m), paypa1.com | Visually identical in many fonts |
| Omission or addition | micosoft.com, microsofft.com | Looks like a typing error |
| Transposition | mircosoft.com | Adjacent letters swapped |
| Different TLD | company.co, company-inc.net | Same name, new registration |
| Subdomain trick | company.com.secure-login.net | The real name is shown first |
| Hyphenation | pay-pal.com | Reads as a brand variant |
| IDN homographs | аpple.com with a Cyrillic а | Punycode in the real address |
Why DMARC cannot help
DMARC proves that a message was sent by an authorized server for the exact From domain. If the attacker registers c0mpany.com and configures SPF, DKIM and DMARC properly, every check passes: they are authenticating their own lookalike domain, not spoofing yours. See email spoofing for the case DMARC does address. Against typosquatting, the recipient''s eye is the only "check".
Where it does damage
Lookalike sender domains are the workhorse of BEC and vendor email compromise: a payment-diversion email from procurement@supp1ier.com reads as normal in a busy inbox. Lookalike domains also host phishing landing pages that mirror real login screens byte for byte.
How to defend
Defensive registration of key variants (common typos, homoglyphs, adjacent TLDs) removes the cheapest options. Brand monitoring surfaces new registrations across the wider space. And email security that measures visual and lexical distance to the domains you actually communicate with catches lookalikes at first contact, before your team ever has to spot the difference.
How Sentaro helps
Sentaro''s Message Defense detects newly registered lookalike domains at first contact in mail flow, comparing their infrastructure and appearance against your organization''s real communication graph. The lookalike does not have to be known to be a bad domain: its behavior betrays it.