Typosquatting

Typosquatting registers domains that resemble legitimate ones to deceive users, a foundation of phishing and BEC that DMARC cannot stop.

Typosquatting is the registration of domains that closely resemble legitimate ones, through misspellings, character swaps or different extensions, to deceive people into trusting fraudulent websites and emails.

Key facts

The techniques

TechniqueExampleWhat it exploits
Misspellinggoggle.com vs google.comTypos in typed URLs and quick reading
Homoglyph / IDNCyrillic "а" swapped for Latin "a"Visually identical characters
TLD swapcompany.co vs company.comUsers not reading past the name
Subdomain deceptionlogin.yourcompany.attacker.comFamiliar strings at the start

Why DMARC cannot help

DMARC proves that a message was sent by an authorized server for the exact From domain. If the attacker registers c0mpany.com and configures SPF, DKIM and DMARC properly, every check passes: they are authenticating their own lookalike domain, not spoofing yours. See email spoofing for the case DMARC does address. Against typosquatting, the recipient''s eye is the only "check".

Where it does damage

Lookalike sender domains are the workhorse of BEC and vendor email compromise: a payment-diversion email from procurement@supp1ier.com reads as normal in a busy inbox. Lookalike domains also host phishing landing pages that mirror real login screens byte for byte.

How to defend

Defensive registration of key variants (common typos, homoglyphs, adjacent TLDs) removes the cheapest options. Brand monitoring surfaces new registrations across the wider space. And email security that measures visual and lexical distance to the domains you actually communicate with catches lookalikes at first contact, before your team ever has to spot the difference.

How Sentaro helps

Sentaro''s Domain Intelligence detects newly registered lookalike domains at first contact in mail flow, comparing their infrastructure and appearance against your organization''s real communication graph. The lookalike does not have to be known to be a bad domain: its behavior betrays it.

Frequently asked questions

What is typosquatting in simple terms?

Registering a domain that looks like a real one (misspelled, in a different extension, or using look-alike characters) to trick people who type or glance at it.

Does DMARC stop lookalike domains?

No. DMARC only checks that mail is authorized for the exact sending domain. A typosquatted domain is a different domain, so the attacker can authenticate it and pass DMARC while still deceiving readers.

What is a homoglyph attack?

Using visually identical or nearly identical characters (often from other alphabets) to build a domain that reads like a real one but is different at the byte level, for example a Cyrillic "а" in place of a Latin "a".

How do we protect our brand from typosquatting?

Defensive registration of the obvious variants, continuous brand monitoring, and behavioral email security that compares incoming senders against your real communication graph rather than relying on domain reputation lists.