Typosquatting (Lookalike Domains)
Definition
Typosquatting is the registration of domains that closely resemble a known brand in order to lead users to phishing or fraud pages through typos or deception.
Updated:
Visuals show sample data.
How blacklens.io covers thisTyposquatting is the registration of domains that look confusingly similar to a known brand or company domain, for example through swapped letters, different endings, inserted hyphens or characters from other alphabets. Such lookalike domains are used for phishing against employees and customers, fake login pages, invoice fraud (business email compromise), malware distribution or simply to intercept traffic.
Why typosquatting matters
A lookalike domain is the infrastructure an attack needs before the first phishing email is sent. Detecting it early means seeing the attack in preparation: the domain is registered, gets a certificate, then MX records for email, then a login page that copies your real one. In invoice fraud the attacker writes from "company-gmbh.com" instead of "company.com" to your customers and asks for payment to a new account. The damage is regularly substantial, and the brand's reputation suffers even though the company itself was never compromised.
How typosquatting detection works
- Permutation: variants are generated systematically from the original domain: typos (blacklens → blacklnes), missing or doubled letters, homoglyphs (l → 1, o → 0, Cyrillic characters), hyphens, additions such as "-login" or "-support", and all relevant top-level domains.
- Checking: for each variant it is checked whether it is registered (RDAP/WHOIS), whether DNS records exist, whether a web or mail server responds and when the registration took place.
- Assessment: screenshots, page content and signals such as password fields, forms posting to foreign domains, use of the brand name, redirects or parking pages separate real threats from harmless registrations.
- Response: collect evidence, file an abuse report with the registrar or host, block in the mail gateway and proxy, warn employees and customers.
How blacklens.io implements typosquatting detection
blacklens.io generates domain permutations daily across 357 top-level domains and 45 special cases, checks RDAP, DNS and reputation, takes screenshots and has every domain assessed by the self-hosted AI (impersonation, suspicious, parked, unrelated, inconclusive, each with a confidence level). Objective signals such as password field, cross-domain form, brand name, redirect, parking and prompt injection are reported separately. A five-criteria evidence gate decides whether there is enough proof for a takedown and generates a pre-filled abuse report. Domains without renewed observation are removed automatically after 60 days.
Can I simply register lookalike domains myself?
For the most important variants (common typos, the usual endings) that is sensible and cheap. It cannot be done completely: thousands of variants can be formed from one domain, and new TLDs keep appearing. Defensive registration and monitoring complement each other.
What is the difference between typosquatting and phishing?
Phishing is the attack; typosquatting is one of its preparations. Not every lookalike domain is used for phishing; some are parked or run for advertising traffic. Conversely, phishing does not necessarily need a lookalike domain. The combination, however, is the most common form of targeted invoice and credential fraud.
How quickly can a malicious domain be taken down?
That depends on the registrar and host: from hours with large providers that have clear abuse processes to weeks with uncooperative registrars. A complete, evidenced abuse report with screenshots, timestamps and proof of trademark rights speeds up the process considerably.
Related terms
Dark Web Monitoring (Darknet Monitoring)
Dark web monitoring continuously searches underground forums, marketplaces, leak sites and stealer logs for…
External Attack Surface Management (EASM)
External attack surface management inventories and monitors from the outside every internet-facing asset of…
Infostealer
An infostealer is malware that collects passwords, session cookies, browser data and files stored on…
See which of these apply to your company.
The free exposure check shows in seconds which systems, technologies and dark web traces of your company are publicly visible.
- 14 days free, all features
- No credit card required
- We walk you through your first findings