Typosquatting: how to find lookalike domains of your brand

    Typosquatting is the registration of domains that look almost like yours, in the hope that a mistyped address, a glanced-at link or a convincing e-mail sender does the rest. Finding those domains is a mechanical exercise. Deciding which ones matter is the part that takes judgement.

    7 min readUpdated September 19, 2026

    The patterns attackers actually use

    Lookalike registrations are not random. They cluster into a few reliable patterns:

    • Omission — a dropped character, easy to miss when reading quickly.
    • Transposition — two adjacent characters swapped, the classic typing error.
    • Lookalike characters — visually similar glyphs substituted, sometimes from other scripts, so the name is near-identical on screen.
    • Hyphenation — a hyphen inserted or removed, which reads as legitimate in most brands.
    • Different domain ending — your exact name under another ending, the most convincing variant of all because the name itself is correct.
    • Added words — a "login", "secure" or "support" label bolted onto your name.

    Finding what has been registered

    Generating the variants is the easy half. The useful half is finding which ones exist, and certificate transparency logs are the best source: almost every site that serves https has a publicly logged certificate, which means names can be discovered even before they are advertised anywhere.

    Fraudpol's free lookalike domain scan combines both: it generates the systematic variants, tests which ones resolve, and searches certificate transparency for registered names you did not think to try.

    Triage: which lookalikes actually matter

    Three signals separate noise from threat, in increasing order of urgency:

    1. It resolves. Someone has pointed it at infrastructure. On its own this only means the name is in use.
    2. It can receive mail. Mail records on a lookalike of your brand have very few innocent explanations. Treat these as priority.
    3. A website answers. Look at what is served. A parking page is monitoring; a copy of your login screen is an incident.

    Record the state you found, with a timestamp, before you act. Content changes and you may need to prove what was there. See brand impersonation protection.

    What to do with the ones that matter

    For a lookalike actively imitating your brand, report to the registrar with your trademark evidence attached, and submit the URL to the browser blocklists at the same time. The steps and the wording are in how to report a phishing site to the registrar, and you can find the right recipient with the abuse contact lookup.

    For the rest, continuous monitoring beats a one-off audit: variants get registered long before they are used. Fraudpol's business plans watch a brand's variant space on a schedule and open a case the moment one goes live — see Fraudpol for companies.

    Have a URL to report right now?

    Fraudpol triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.

    Report a website to Fraudpol

    Frequently asked questions

    Is every lookalike domain an attack?

    No. Many are held by domain investors, some by unrelated businesses, and some are genuine coincidences with short or generic names. What turns a lookalike into a threat is use: a website that imitates your brand, or mail records that let it send messages appearing to come from you.

    Which variant is the most dangerous in practice?

    A variant that can send e-mail. Credential phishing and invoice fraud usually arrive by mail, and a lookalike sender domain is far more convincing than a free mailbox. A variant with mail records and no website is not harmless — it is often the setup phase.

    Should we defensively register every variant?

    That is not realistic; the variant space is effectively unlimited. Registering the handful closest to your main name and the endings your customers assume is reasonable. Beyond that, monitoring is more cost-effective than acquisition.