← Glossary

Typosquatting

Typosquatting registers domains that resemble legitimate ones to deceive users, a foundation of phishing and BEC that DMARC cannot stop.

Updated

Typosquatting is the registration of domains that closely resemble legitimate ones, through misspellings, character swaps or different extensions, to deceive people into trusting fraudulent websites and emails.

Key facts

  • It is the infrastructure behind much phishing and business email compromise: the lookalike sender that carries the fraud.
  • DMARC does not stop it, because the attacker owns the lookalike domain and can authenticate it perfectly.
  • Techniques include misspellings (goggle.com), homoglyphs (visually similar characters), and alternate TLDs (company.co vs company.com).

The techniques

TechniqueExampleHow it works
Misspellinggoggle.com for google.comRelies on fast reading
Homoglyphsrnicrosoft.com (rn for m), paypa1.comVisually identical in many fonts
Omission or additionmicosoft.com, microsofft.comLooks like a typing error
Transpositionmircosoft.comAdjacent letters swapped
Different TLDcompany.co, company-inc.netSame name, new registration
Subdomain trickcompany.com.secure-login.netThe real name is shown first
Hyphenationpay-pal.comReads as a brand variant
IDN homographsаpple.com with a Cyrillic аPunycode in the real address

Why DMARC cannot help

DMARC proves that a message was sent by an authorized server for the exact From domain. If the attacker registers c0mpany.com and configures SPF, DKIM and DMARC properly, every check passes: they are authenticating their own lookalike domain, not spoofing yours. See email spoofing for the case DMARC does address. Against typosquatting, the recipient''s eye is the only "check".

Where it does damage

Lookalike sender domains are the workhorse of BEC and vendor email compromise: a payment-diversion email from procurement@supp1ier.com reads as normal in a busy inbox. Lookalike domains also host phishing landing pages that mirror real login screens byte for byte.

How to defend

Defensive registration of key variants (common typos, homoglyphs, adjacent TLDs) removes the cheapest options. Brand monitoring surfaces new registrations across the wider space. And email security that measures visual and lexical distance to the domains you actually communicate with catches lookalikes at first contact, before your team ever has to spot the difference.

How Sentaro helps

Sentaro''s Message Defense detects newly registered lookalike domains at first contact in mail flow, comparing their infrastructure and appearance against your organization''s real communication graph. The lookalike does not have to be known to be a bad domain: its behavior betrays it.

Questions we get asked.

What is typosquatting in simple terms?

Registering a domain that looks like a real one (misspelled, in a different extension, or using look-alike characters) to trick people who type or glance at it.

Does DMARC stop lookalike domains?

No. DMARC only checks that mail is authorized for the exact sending domain. A typosquatted domain is a different domain, so the attacker can authenticate it and pass DMARC while still deceiving readers.

What is a homoglyph attack?

Using visually identical or nearly identical characters (often from other alphabets) to build a domain that reads like a real one but is different at the byte level, for example a Cyrillic "а" in place of a Latin "a".

How do we protect our brand from typosquatting?

Defensive registration of the obvious variants, continuous brand monitoring, and behavioral email security that compares incoming senders against your real communication graph rather than relying on domain reputation lists.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.