Skip to content

Typosquatting

In plain terms

An address that's almost identical to the one you wanted: one letter short, an extra hyphen, a different extension. The page looks like the real site, but it belongs to someone else.

Definition

Typosquatting consists of registering a domain name very close to a legitimate site — a missing letter, a swap, a different extension — to catch visitors who mistype the address or read too quickly.

How it works

The attacker registers plausible variants of the targeted domain: a common typo, a doubled or missing letter, an added hyphen, a different extension. The hosted site copies the appearance of the original. The visitor, convinced they're in the right place, logs in as usual. The technique is often combined with phishing: the deceptive domain serves as the destination of a link sent by email or text, where it looks credible at a glance.

Warning signs

  • Address almost identical to the expected one, off by a letter or character
  • Unusual extension for the organization concerned
  • Hyphen inserted into a domain name that doesn't usually have one
  • Login page requesting credentials after a link received by message
  • Missing usual personalized elements once "logged in"

How to verify

Read the address starting from the end of the domain name, just before the first forward slash: that part determines who actually owns the site. The safest approach is not to type the address at all, and to use a bookmark saved once and for all.

What to do

Don't enter any credentials. Leave the page and reach the site through a bookmark or the official app.

If it already happened

Immediately change the password of the affected service, as well as any account reusing the same password. Enable two-factor authentication and check the account's recent logins.

Frequently asked questions

What's the difference with a homoglyph attack?
Typosquatting uses ordinary characters arranged differently — a credible typo. A homoglyph attack uses different characters that look visually identical, which makes it undetectable by simply reading the address.
The padlock was displayed, wasn't the site secure?
The padlock only indicates that the connection is encrypted, not that the site is legitimate. Any site, including a fraudulent one, can obtain a certificate.

Official sources

This article is part of the Website and browser attacks family. Last updated: 2026-08-31.