Most phishing training tells employees to check the sender's domain before trusting an email. Typosquatting is built to beat that exact habit. Instead of spoofing your domain outright, an attacker registers one that's close enough to pass a quick glance — ghosxt-support.com instead of ghosxt.com, a swapped letter, or a different ending entirely — and uses it to send invoices, password-reset lures, or urgent requests that look like they came from inside your business or from a vendor you already trust.
How a lookalike domain gets built and used
Registering the domain itself takes minutes and costs less than dinner. The common patterns are character swaps (rn for m, 0 for o), an inserted hyphen, a doubled letter, or a different top-level ending (.net, .co, .biz instead of .com). Some attacks go further with homograph tricks, using look-alike characters from other alphabets that render almost identically in a browser address bar. Once the domain exists, it gets paired with a matching email setup and, often, a cloned copy of a real login page or invoice template — enough polish that the domain is the only thing actually wrong.
Why this is a real risk for a small business
Typosquatting rarely stands alone; it's usually the delivery method for another attack:
- Vendor impersonation and invoice fraud. A lookalike domain sends a "updated bank details" email that appears to come from a supplier you actually pay, redirecting a real invoice payment to an attacker's account.
- Brand impersonation aimed at your customers. A domain built to look like yours can send phishing email or host a fake payment page under your name, damaging trust you can't easily win back.
- A boost to business email compromise. Combined with an urgent tone and a plausible reply-to address, a lookalike domain makes an executive-impersonation request far more convincing.
- It costs the attacker almost nothing. Cheap registration and no need to actually breach your systems make this one of the lowest-effort attacks available, which is why it keeps showing up.
What actually stops it
- DMARC set to enforce, not just monitor, so mail claiming to be from your real domain fails without a valid SPF/DKIM alignment — this doesn't stop a lookalike domain from existing, but it does stop attackers from spoofing your exact domain in the first place.
- A handful of defensive registrations covering the most obvious typos and alternate endings of your own domain, rather than trying to own every possible variation.
- A callback verification policy for any change to payment details or banking information, using a phone number you already have on file — not one in the email.
- Domain monitoring that flags new registrations closely matching your business name, so you find out before a lookalike domain is used against you or your customers.
- Training that emphasizes hovering and pasting the actual domain into a text field to compare character-by-character, since a quick visual scan is exactly what these attacks are built to survive.
Where this fits
- The business email compromise post, for how a lookalike domain often supports an executive-impersonation attack.
- The SPF/DKIM/DMARC post, for the technical fix that stops your own domain from being spoofed outright.
- The domain security post, for protecting the domain and registrar account you actually own.
- The vendor risk management post, for the invoice and payment-change verification habits that catch this before money moves.
- The cybersecurity page, for where email authentication and brand monitoring fit into a full security program.
FAQs about typosquatting
What's the difference between typosquatting and phishing?
Typosquatting is the infrastructure; phishing is often what it's used for. Typosquatting is registering a domain that looks almost identical to a real one — yours or a vendor's — by swapping a letter, adding a hyphen, or using a different ending. That lookalike domain then gets used to send phishing emails, host a fake login page, or receive replies to a spoofed invoice, all of which look more convincing because the domain passes a quick visual check. Not every typosquatted domain is used for phishing right away; some sit unused for months, or get used to intercept typos from people mistyping a real address.
Do I need to register every possible misspelling of my domain?
No, and trying to is a losing game — there are thousands of character-swap and TLD combinations for any domain name. It's worth registering the handful of common typos and the most obvious alternate endings (.net, .co, .biz) if they're cheap and available, but the higher-leverage move is DMARC enforcement, so attackers can't send email that appears to come from your real domain even if they own a similar-looking one, plus watching for new lookalike registrations so you catch the ones that matter.
How would I know if someone is impersonating my business with a lookalike domain?
The most common tip-off is a customer or vendor forwarding you an email that claims to be from you but wasn't, often because they noticed the reply address looked slightly off or the request itself seemed unusual (a change to payment details, an urgent invoice). Domain monitoring services can also flag new registrations that closely match your name before they're ever used against you, which is worth having if your business relies on email-based invoicing or client communication.
Not sure if DMARC is actually enforcing on your domain?
30 minutes with a DoD-cleared engineer. We'll check your SPF, DKIM, and DMARC configuration, look for lookalike domains already registered against your name, and build a payment-verification policy that stops invoice fraud before money moves.
Book your free security assessment