[{"data":1,"prerenderedAt":99},["ShallowReactive",2],{"glossary:typosquatting":3},{"term":4,"published":91,"modified":91,"mentions":92,"related":98},{"slug":5,"title":6,"lede":7,"blocks":8,"faqs":78},"typosquatting","Typosquatting","Typosquatting registers domains that resemble legitimate ones to deceive users, a foundation of phishing and BEC that DMARC cannot stop.",[9,12,15,21,23,62,64,66,68,70,72,74,76],{"t":10,"text":11},"p","Typosquatting is the registration of domains that closely resemble legitimate ones, through misspellings, character swaps or different extensions, to deceive people into trusting fraudulent websites and emails.",{"t":13,"text":14},"h2","Key facts",{"t":16,"items":17},"ul",[18,19,20],"It is the infrastructure behind much phishing and business email compromise: the lookalike sender that carries the fraud.","DMARC does not stop it, because the attacker owns the lookalike domain and can authenticate it perfectly.","Techniques include misspellings (goggle.com), homoglyphs (visually similar characters), and alternate TLDs (company.co vs company.com).",{"t":13,"text":22},"The techniques",{"t":24,"rows":25},"table",[26,30,34,38,42,46,50,54,58],[27,28,29],"Technique","Example","How it works",[31,32,33],"Misspelling","goggle.com for google.com","Relies on fast reading",[35,36,37],"Homoglyphs","rnicrosoft.com (rn for m), paypa1.com","Visually identical in many fonts",[39,40,41],"Omission or addition","micosoft.com, microsofft.com","Looks like a typing error",[43,44,45],"Transposition","mircosoft.com","Adjacent letters swapped",[47,48,49],"Different TLD","company.co, company-inc.net","Same name, new registration",[51,52,53],"Subdomain trick","company.com.secure-login.net","The real name is shown first",[55,56,57],"Hyphenation","pay-pal.com","Reads as a brand variant",[59,60,61],"IDN homographs","аpple.com with a Cyrillic а","Punycode in the real address",{"t":13,"text":63},"Why DMARC cannot help",{"t":10,"text":65},"DMARC proves that a message was sent by an authorized server for the exact From domain. If the attacker registers c0mpany.com and configures SPF, DKIM and DMARC properly, every check passes: they are authenticating their own lookalike domain, not spoofing yours. See email spoofing for the case DMARC does address. Against typosquatting, the recipient''s eye is the only \"check\".",{"t":13,"text":67},"Where it does damage",{"t":10,"text":69},"Lookalike sender domains are the workhorse of BEC and vendor email compromise: a payment-diversion email from procurement@supp1ier.com reads as normal in a busy inbox. Lookalike domains also host phishing landing pages that mirror real login screens byte for byte.",{"t":13,"text":71},"How to defend",{"t":10,"text":73},"Defensive registration of key variants (common typos, homoglyphs, adjacent TLDs) removes the cheapest options. Brand monitoring surfaces new registrations across the wider space. And email security that measures visual and lexical distance to the domains you actually communicate with catches lookalikes at first contact, before your team ever has to spot the difference.",{"t":13,"text":75},"How Sentaro helps",{"t":10,"text":77},"Sentaro''s Message Defense detects newly registered lookalike domains at first contact in mail flow, comparing their infrastructure and appearance against your organization''s real communication graph. The lookalike does not have to be known to be a bad domain: its behavior betrays it.",[79,82,85,88],{"q":80,"a":81},"What is typosquatting in simple terms?","Registering a domain that looks like a real one (misspelled, in a different extension, or using look-alike characters) to trick people who type or glance at it.",{"q":83,"a":84},"Does DMARC stop lookalike domains?","No. DMARC only checks that mail is authorized for the exact sending domain. A typosquatted domain is a different domain, so the attacker can authenticate it and pass DMARC while still deceiving readers.",{"q":86,"a":87},"What is a homoglyph attack?","Using visually identical or nearly identical characters (often from other alphabets) to build a domain that reads like a real one but is different at the byte level, for example a Cyrillic \"а\" in place of a Latin \"a\".",{"q":89,"a":90},"How do we protect our brand from typosquatting?","Defensive registration of the obvious variants, continuous brand monitoring, and behavioral email security that compares incoming senders against your real communication graph rather than relying on domain reputation lists.","2026-09-08",[93,94,95,96,97],"business-email-compromise","dmarc","spoofing","phishing","vendor-email-compromise",[95,94,97],1789658069493]