Typosquatting Explained: How Fake Versions of Your Domain Trick Customers

Everyone mistypes a web address now and then. Typosquatting is a form of online fraud that turns those small slips into a way of catching your customers. This guide explains what typosquatting is, the common patterns scammers use, and what a business can do to protect its customers and its name. It is written in plain English for business owners, not technical staff.

What Typosquatting Means

Typosquatting is when someone registers a web address that is a slight misspelling of a real one, hoping to catch people who make a typing mistake. The word is a blend of "typo" and "squatting": the fraudster is squatting on the typo, waiting for visitors to arrive by accident.

If your business is at "brightpath.co.uk", a typosquatter might register "brihtpath.co.uk", "brightpaht.co.uk" or "brigthpath.co.uk". To a busy customer glancing at the address bar, any of those can look close enough to be real. Typosquatting is a common form of the wider problem we cover in our guide to domain impersonation.

The Common Typo Patterns

Fraudsters do not guess at random. They use well-known patterns that match the mistakes people actually make, and they often register dozens of variations at once. The main patterns are worth recognising.

Missing letters, where a single character is dropped, such as "brightpth.co.uk".

Extra or doubled letters, such as "brightpaath.co.uk".

Swapped letters, where two characters are transposed, such as "brihgtpath.co.uk".

Neighbouring-key slips, where a letter is replaced by one next to it on the keyboard, such as "brigjtpath.co.uk".

Wrong ending, where the name is spelled correctly but the ending is changed, such as ".com" instead of ".co.uk", or ".net" instead of ".com".

Because these patterns are predictable, software can generate many likely misspellings of your name in seconds. That makes the attack easy to attempt, but it also lets a monitoring service watch a broad set of variations on your behalf.

Why Typosquatting Works on Your Customers

People often recognise the overall shape of a familiar name rather than checking every letter. On a small screen or in a hurried message, a near-match can pass unnoticed.

Once they arrive, a typosquatting site can do several things. It might show a copy of your website to take fraudulent orders or steal login details. It might quietly redirect visitors to adverts or another site. The domain can also be used in deceptive messages and fake invoices that appear to come from a business almost identical to yours.

A Simple Example

Imagine a plumbing supplier at "coretubes.co.uk". A fraudster registers "cortubes.co.uk", missing a single letter, and builds a near-perfect copy of the real site. A regular customer types the address from memory, drops the "e", and lands on the fake. They place what they think is a normal order and enter their card details. The customer has been defrauded, and as far as they are concerned it happened on the real company's website. The genuine business may not hear about it until the complaints start, by which point the damage to trust is done.

How to Protect Your Business from Typosquatting

There are three practical steps.

Register selected high-priority misspellings yourself. Buying and renewing a handful of close typos or common alternative endings can keep those exact domains under your control. You cannot buy every possible variation, so our guide to defensive domain registration explains how to prioritise.

Keep watch for the rest. Since you cannot register them all, the practical safety net is to be told when a misspelling of your name is registered by someone else. Checking for this by hand would mean regenerating and testing every variation over and over, which is not realistic for a working business. This is precisely the job Impostor Watch does automatically.

Act quickly when one appears. A typosquatting domain deserves closer attention when it hosts a live website or has mail records configured. The sooner you know, the sooner you can gather evidence and report any abuse. Our guide on what to do when you find a fake version of your website walks through the steps.

How Impostor Watch Helps

Impostor Watch uses public Certificate Transparency logs, newly registered domain feeds and generated variations to look for likely misspellings of your name. When it finds a match, it checks for a live website, mail records and signs such as a copy of your site's small browser icon (its favicon), then explains the apparent risk in plain English.

That means you do not have to imagine every possible typo, or check for them yourself, or work out which ones matter. And if a typosquatting site needs removing, you can ask us to handle it for you. You can start with a one-off report or turn on continuous monitoring for a small monthly fee.

Frequently Asked Questions

Is typosquatting illegal?

Registering a misspelling is not automatically unlawful. Using one for fraud, passing off or trade mark infringement may be. Clear evidence of how the domain is being used will strengthen a provider report or formal dispute, but removal is not guaranteed.

Should I buy every misspelling of my domain?

No, that is neither practical nor necessary. Buy the closest and most likely typos and the common alternative endings, then rely on monitoring to catch anything else a fraudster registers.

How would I know if someone is typosquatting my business?

You might hear about it from a confused customer, but that may mean it has already caused harm. A monitoring service such as Impostor Watch can alert you when its certificate, registration or DNS checks detect a matching domain, giving you a chance to assess it earlier.

Want to know which misspellings may be active in DNS? Run a free scan with Impostor Watch to see which generated variations are registered and point to an internet address.

Check for lookalike domains

Run a free check for lookalike domains that are registered and point to an internet address — no sign-up, nothing to install.

Run a free scan Or see a sample Domain Report →