Typosquatting
In plain terms
An address that's almost identical to the one you wanted: one letter short, an extra hyphen, a different extension. The page looks like the real site, but it belongs to someone else.
Definition
Typosquatting consists of registering a domain name very close to a legitimate site — a missing letter, a swap, a different extension — to catch visitors who mistype the address or read too quickly.
How it works
The attacker registers plausible variants of the targeted domain: a common typo, a doubled or missing letter, an added hyphen, a different extension. The hosted site copies the appearance of the original. The visitor, convinced they're in the right place, logs in as usual. The technique is often combined with phishing: the deceptive domain serves as the destination of a link sent by email or text, where it looks credible at a glance.
Warning signs
- Address almost identical to the expected one, off by a letter or character
- Unusual extension for the organization concerned
- Hyphen inserted into a domain name that doesn't usually have one
- Login page requesting credentials after a link received by message
- Missing usual personalized elements once "logged in"
How to verify
Read the address starting from the end of the domain name, just before the first forward slash: that part determines who actually owns the site. The safest approach is not to type the address at all, and to use a bookmark saved once and for all.
What to do
Don't enter any credentials. Leave the page and reach the site through a bookmark or the official app.
If it already happened
Immediately change the password of the affected service, as well as any account reusing the same password. Enable two-factor authentication and check the account's recent logins.
Frequently asked questions
- What's the difference with a homoglyph attack?
- Typosquatting uses ordinary characters arranged differently — a credible typo. A homoglyph attack uses different characters that look visually identical, which makes it undetectable by simply reading the address.
- The padlock was displayed, wasn't the site secure?
- The padlock only indicates that the connection is encrypted, not that the site is legitimate. Any site, including a fraudulent one, can obtain a certificate.
Related attacks
Official sources
This article is part of the Website and browser attacks family. Last updated: 2026-08-31.