DigitalMANIPULATIVE

Typosquatting Domains

What it is

Registering web domains that look like a trusted one — a misspelling, a swapped letter, a different top-level domain, a lookalike character — so that the site is mistaken for the original by readers, search engines, and anyone who glances at a link.

How it works

People read domains the way they read words, by shape rather than letter by letter, and a domain is the strongest single cue to a page's source. Typosquatting exploits both facts. Agten and colleagues (2015), monitoring registrations around popular domains for seven months, found squatters systematically occupying misspellings and near-variants of well-known sites, mostly for ad revenue, with a minority used for phishing and malware. Information operations adopted the same mechanism for credibility rather than clicks. The Doppelganger operation, first documented by EU DisinfoLab in 2022, cloned the design of Le Monde, Bild, the Guardian, and the Washington Post on domains such as washingtonpost.pm and published fabricated articles; the fake pages carried the masthead's authority for as long as it took a reader to scan the address. Internationalized domain names allow a further variant, the homograph attack, in which a Cyrillic or Greek letter replaces a Latin one so that the address is visually identical. The tell is always in the address bar, which is exactly where readers do not look.

Real-world examples

  • In September 2024, the U.S. Justice Department seized 32 domains used by the Russian Doppelganger operation, including lookalikes of the Washington Post and Fox News, and published an affidavit describing how fabricated articles on the clones were seeded through paid social ads and fake accounts.
  • In July 2015, a site at bloomberg.market, styled as Bloomberg, published a fabricated story that Twitter had received a 31-billion-dollar takeover offer; Twitter's shares jumped about eight percent before the hoax was exposed.
  • During the 2016 U.S. election, abcnews.com.co, unrelated to ABC News, published fabricated stories that spread widely on Facebook; its operator, Paul Horner, told the Washington Post that his readers did not check anything.
  • In April 2017, security researcher Xudong Zheng demonstrated a homograph attack by registering a domain using Cyrillic characters that major browsers rendered as apple.com, prompting browser vendors to change how such names are displayed.

Ethical guidelines

  • Registering a domain designed to be mistaken for another party's is deception at the moment of registration, before any content is published.
  • Criticism and parody sites should carry names that signal their nature; a critic who hides behind a lookalike domain forfeits the credibility of the criticism.
  • Publishers have an obligation to secure obvious variants of their own domains and to warn readers about known clones.

How to defend against it

  • Read the address, not the page: check the domain immediately left of the first single slash, including the top-level domain, and be suspicious of any variant (.co, .pm, .info, an extra word) of an outlet you know.
  • Reach trusted sites through your own bookmarks or by typing the address rather than through links in messages and posts; a link is an invitation to a domain someone else chose.
  • When a story from a major outlet exists only on the page you were linked to, search the outlet's own site for the headline; a clone's articles never appear on the real site.
  • Look for homograph tells — an address that looks right but shows a certificate warning, a string beginning xn-- when copied, or letters that render slightly differently.
  • Organizations should defensively register common misspellings and alternate top-level domains of their own names and monitor certificate-transparency logs for lookalikes.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Agten, P., Joosen, W., Piessens, F., & Nikiforakis, N. (2015). Seven Months' Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse. Proceedings of the Network and Distributed System Security Symposium (NDSS 2015)
    Longitudinal measurement of typosquatting registrations around popular domains and their uses.
  2. EU DisinfoLab (2022). Doppelganger: Media clones serving Russian propaganda. EU DisinfoLab
    The cloning of major European news brands on lookalike domains to publish fabricated articles.
  3. U.S. Department of Justice (2024). Justice Department Disrupts Covert Russian Government-Sponsored Influence Operation Targeting Audiences in the United States and Elsewhere. Office of Public Affairs press release and accompanying affidavit, September 4, 2024
    The seizure of 32 Doppelganger domains and the description of how the clones were seeded.
Last reviewed
Suggest a correction

Detect Typosquatting Domains in any text

Paste any message, email, or article into our free Manipulation Detector to see if Typosquatting Domains or other techniques are being used on you.

Related Articles