What Is Typosquatting? How to Protect Your Business
Typosquatting registers misspelled or lookalike versions of legitimate domains to trick users into visiting fraudulent websites. Criminals use it for phishing, malware delivery and brand impersonation — and UK businesses need both technical and monitoring defences.
Nathan Hill-Haimes
Technical Director
Nathan Hill-Haimes, Technical Director | 7 min read · Mar 2026
What is typosquatting?
Typosquatting — also called URL hijacking or domain mimicry — means registering domain names that are slight variations of a legitimate domain, designed to catch people who mistype a URL or do not look closely. A criminal might register amv1a.co.uk or amvla.co.uk to impersonate amvia.co.uk, betting that many readers will not spot the difference in a phishing email or a browser address bar.
Domain registration is cheap — a.co.uk domain costs a few pounds per year — so an attacker can register dozens of variants of a target domain for very little. The potential return from one successful phishing attack dwarfs that outlay, which makes typosquatting an economically rational tactic for criminals targeting a specific business or brand. It sits alongside email impersonation as a core ingredient of modern phishing protection thinking, and it is why domain-level monitoring belongs in any serious managed cybersecurity programme.
How do typosquatting attacks actually work?
Typosquatting is rarely the whole attack — it is the prop that makes the real attack convincing. The lookalike domain lends false legitimacy to a phishing email, a cloned login page, or a hijacked supplier conversation. Below are the four patterns we see most often against UK SMEs.
Phishing via email
Typosquatted domains are frequently used as the sending domain for phishing emails. An email from `accounts@barclays-online-secure.co.uk` looks convincing to a recipient who does not examine the full domain. The typosquatted domain passes some technical checks — it has its own SPF, DKIM and DMARC records — because it is a genuinely registered domain, just not the real brand's domain. Phishing remains the most common type of breach reported by UK businesses, according to the government's Cyber Security Breaches Survey 2025.
Fake websites
A typosquatted domain can host a website that visually mimics the legitimate business — same design, same content, cloned from the real site — with a login form that quietly steals the credentials people enter after landing there by mistake. This works especially well against businesses with public-facing login portals, where users expect to type a username and password.
Business email compromise support
Criminals running business email compromise (BEC) attacks sometimes place a typosquatted domain in the reply-to address of an email that appears to come from a real supplier. Replies from the victim go to the criminal's inbox rather than the genuine supplier's, letting them intercept and steer the conversation — often towards a fraudulent change of bank details.
Software package hijacking
A specific variant targets developers who install packages from repositories like npm or PyPI. A malicious package named `reqests` instead of `requests` can be installed by accident and run hostile code inside a development or production environment. The same human reflex — not reading carefully — that powers email typosquatting powers this supply-chain version too.
Who is most at risk from typosquatting?
Any business with a public-facing web presence and a recognisable brand is a potential target. The highest-risk categories are those where a stolen login or a redirected payment causes immediate financial or regulatory damage, and where customers routinely receive emails carrying the brand's domain.
- Financial services firms with online client portals
- Professional services firms — law firms, accountants — whose domains appear in client communications involving money
- E-commerce businesses where users log in and enter payment details
- Any business with a well-known brand attackers can borrow to build credibility
SMEs are not immune. Criminals often pick smaller firms precisely because they are less likely to have brand or domain monitoring in place than large corporations — a gap AMVIA closes as part of a single, accountable security service.
How do you detect a typosquatting attack?
The primary detection tool is domain monitoring. Services that watch newly registered domains for variations of your brand name can alert you within hours of a typosquatted domain being registered — giving you time to investigate and, if needed, pursue takedown before it is weaponised. Speed matters because the damage starts the moment the domain is used, not the moment it is registered.
Free tools such as dnstwist generate lists of likely typosquatting variants of a domain and check whether they are already registered. Commercial brand-protection services add automated monitoring, alerting and takedown assistance. The NCSC also runs a Suspicious Email Reporting Service that helps remove malicious sites once they appear.
How do you protect your business from typosquatting?
Effective protection is layered, because no single control stops every variant. The combination below removes the easiest attack routes, surfaces the rest quickly, and gives your staff the awareness to catch what slips through.
| Control | What it does | Limitation |
|---|---|---|
| Defensive domain registration | Removes the most obvious lookalike domains from the market | Cannot cover every possible variant |
| Domain monitoring | Alerts you when a new lookalike domain is registered | Detects, does not prevent registration |
| Staff and customer awareness | Trains people to check domains before entering credentials | Depends on consistent human vigilance |
| Email security gateway with impersonation detection | Catches near-match domain impersonation in inbound email | Protects email, not web or developer tooling |
Working through that stack in practice:
- Defensive domain registration: Register the most likely typosquatting variants of your primary domain — common misspellings, singular/plural forms, hyphenated versions — and redirect them to your real site. A five-domain defensive registration might cost £20-50 per year. It is not feasible to register every possible variant, which is why this pairs with monitoring.
- Domain monitoring: Automated monitoring for new registrations that closely resemble yours, with alerting so you can investigate suspicious registrations quickly.
- Staff and customer awareness: Train staff to read the full domain before entering credentials, and warn customers to verify the URL they are visiting.
- Email security gateway with impersonation detection: A gateway that flags near-match domain impersonation in inbound email adds a technical layer against typosquatted phishing. AMVIA delivers this through the email security controls in the Barracuda suite.
A common misconception is that authentication on your own domain solves the problem. Enforcing DMARC at `p=reject` stops criminals sending email as your exact domain — see our guide to email spoofing for how that works — but it does nothing against typosquatted domains, which are independently registered and carry their own DMARC records. Those still require monitoring and defensive registration.
Is Your Business Domain Being Imitated?
Typosquatted domains can be active for weeks before a business notices. AMVIA can check for existing lookalike domains and put monitoring in place to alert you to future registrations.
Frequently Asked Questions
Registering a domain to profit from or harm a brand can be challenged under the Nominet Dispute Resolution Service (DRS) for.co.uk domains, and through ICANN's Uniform Domain-Name Dispute-Resolution Policy (UDRP) for generic top-level domains. Criminal intent may also engage the Fraud Act 2006. Enforcement through these routes takes time, so prevention and monitoring are more practical than relying on legal action alone.
For.co.uk domains, file a complaint with Nominet under their DRS. For.com and other gTLDs, the ICANN UDRP process applies. The NCSC's reporting service can assist with takedowns of sites hosting phishing content, and active fraud should be reported to Action Fraud. Brand-protection services, or a managed security partner, can handle this process on your behalf.
Registering the most obvious variants — one-character substitutions, common misspellings, your domain with and without hyphens, and the most common TLDs (.co.uk,.com,.org.uk) — gives meaningful protection at modest cost. A five-domain defensive registration might cost £20-50 per year. You cannot register every variant, so domain monitoring is the necessary complement.
Yes, indirectly. If a typosquatted domain sends large volumes of phishing email impersonating your brand, recipients and email providers may start associating phishing characteristics with your brand even though your real domain is uninvolved. That can dent deliverability and trust. Rapid detection and takedown of typosquatted phishing domains is the most effective mitigation.
Cybersquatting means registering a domain that matches a well-known trademark — for example registering fordcars.co.uk before Ford does — to sell it to the owner or profit from the association. Typosquatting is specifically about misspellings and close variants that catch users who make errors. Both are forms of bad-faith domain registration, but the intent and mechanics differ.
No. DMARC protects your exact domain from being spoofed in email. It does not stop typosquatted domains, which are separately registered and have their own DMARC records. A `p=reject` policy prevents criminals sending email as your exact domain, but they can still send from a visually similar typosquatted domain that DMARC cannot detect.
Related Reading
What Is DMARC?
How DMARC protects your exact domain from spoofing — and where its protection ends.
Email Spoofing: How to Detect and Prevent It
The relationship between domain spoofing, typosquatting and email authentication controls.
Email Phishing: Keeping Your Business Safe
How typosquatted domains are used in phishing campaigns and the layered controls that stop them.