Typosquatting Domains
What it is
Registering web domains that look like a trusted one — a misspelling, a swapped letter, a different top-level domain, a lookalike character — so that the site is mistaken for the original by readers, search engines, and anyone who glances at a link.
How it works
Real-world examples
- •In September 2024, the U.S. Justice Department seized 32 domains used by the Russian Doppelganger operation, including lookalikes of the Washington Post and Fox News, and published an affidavit describing how fabricated articles on the clones were seeded through paid social ads and fake accounts.
- •In July 2015, a site at bloomberg.market, styled as Bloomberg, published a fabricated story that Twitter had received a 31-billion-dollar takeover offer; Twitter's shares jumped about eight percent before the hoax was exposed.
- •During the 2016 U.S. election, abcnews.com.co, unrelated to ABC News, published fabricated stories that spread widely on Facebook; its operator, Paul Horner, told the Washington Post that his readers did not check anything.
- •In April 2017, security researcher Xudong Zheng demonstrated a homograph attack by registering a domain using Cyrillic characters that major browsers rendered as apple.com, prompting browser vendors to change how such names are displayed.
Ethical guidelines
- ●Registering a domain designed to be mistaken for another party's is deception at the moment of registration, before any content is published.
- ●Criticism and parody sites should carry names that signal their nature; a critic who hides behind a lookalike domain forfeits the credibility of the criticism.
- ●Publishers have an obligation to secure obvious variants of their own domains and to warn readers about known clones.
How to defend against it
- ►Read the address, not the page: check the domain immediately left of the first single slash, including the top-level domain, and be suspicious of any variant (.co, .pm, .info, an extra word) of an outlet you know.
- ►Reach trusted sites through your own bookmarks or by typing the address rather than through links in messages and posts; a link is an invitation to a domain someone else chose.
- ►When a story from a major outlet exists only on the page you were linked to, search the outlet's own site for the headline; a clone's articles never appear on the real site.
- ►Look for homograph tells — an address that looks right but shows a certificate warning, a string beginning xn-- when copied, or letters that render slightly differently.
- ►Organizations should defensively register common misspellings and alternate top-level domains of their own names and monitor certificate-transparency logs for lookalikes.
From the Defense Playbook
A four-move routine for anything you meet online: Stop, Investigate the source, Find better coverage, and Trace claims, quotes, and media to their original context; it takes under a minute and replaces the instinct to study the page itself.
To judge an unfamiliar website, leave it: open new tabs and find out what independent sources say about the organization behind it, before spending any time on the site's own content, design, or "About" page.
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Agten, P., Joosen, W., Piessens, F., & Nikiforakis, N. (2015). Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse. Proceedings of the Network and Distributed System Security Symposium (NDSS 2015)Longitudinal measurement of typosquatting registrations around popular domains and their uses.
- EU DisinfoLab (2022). Doppelganger: Media clones serving Russian propaganda. EU DisinfoLabThe cloning of major European news brands on lookalike domains to publish fabricated articles.
- U.S. Department of Justice (2024). Justice Department Disrupts Covert Russian Government-Sponsored Influence Operation Targeting Audiences in the United States and Elsewhere. Office of Public Affairs press release and accompanying affidavit, September 4, 2024The seizure of 32 Doppelganger domains and the description of how the clones were seeded.
Related Articles
Dark Patterns in UX: How Apps Manipulate Your Behavior
Subscription traps, misleading interfaces, and engineered addiction. Understanding the persuasion techniques built into the apps you use every day.
OSINT for Beginners: Open Source Intelligence Explained
Open Source Intelligence (OSINT) uses publicly available data to gather actionable insights. Here is a beginner-friendly guide to what OSINT is and how it is used.