Typosquatting, also called URL hijacking, a sting site, a cousin domain, or a fake URL, is a form of
cybersquatting, and possibly
brandjacking which relies on mistakes such as
typos made by Internet users when inputting a
website address into a
web browser
A web browser, often shortened to browser, is an application for accessing websites. When a user requests a web page from a particular website, the browser retrieves its files from a web server and then displays the page on the user's scr ...
. A user accidentally entering an incorrect website address may be led to any URL, including an alternative website owned by a cybersquatter.
The typosquatter's
URL will usually be ''similar'' to the victim's site address; the typosquatting site could be in the form of:
*A misspelling, or foreign language spelling, of the intended site
*A misspelling based on a typographical error
*A plural of a singular domain name
*A different
top-level domain
A top-level domain (TLD) is one of the domain name, domains at the highest level in the hierarchical Domain Name System of the Internet after the root domain. The top-level domain names are installed in the DNS root zone, root zone of the nam ...
(e.g., .com instead of .org)
*An abuse of the
Country Code Top-Level Domain
A country code top-level domain (ccTLD) is an Internet top-level domain generally used or reserved for a country, sovereign state, or dependent territory identified with a country code. All ASCII ccTLD identifiers are two letters long, and all tw ...
(ccTLD) (
.cm,
.co, or
.om instead of .com)
Similar abuses:
*Combosquatting – no misspelling, but appending an arbitrary word that appears legitimate, but that anyone could register.
*
Doppelganger domain – omitting a period or inserting an extra period
*Appending terms such as ''sucks'' or -' to a domain name
Once on the typosquatter's site, the user may also be tricked into thinking that they are actually on the real site through the use of copied or similar logos, website layouts, or content. Spam emails sometimes make use of typosquatting URLs to trick users into visiting malicious sites that look like a given bank's site, for instance.
Motivation
There are several different reasons for typosquatters buying a typo domain:
*To try to sell the typo domain back to the brand owner
*To
monetize the domain through
advertising
Advertising is the practice and techniques employed to bring attention to a Product (business), product or Service (economics), service. Advertising aims to present a product or service in terms of utility, advantages, and qualities of int ...
revenues from direct navigation misspellings of the intended domain
*To redirect the typo-traffic to a competitor
*To redirect the typo-traffic back to the brand itself, but through an affiliate link, thus earning commissions from the brand owner's affiliate program
*As a
phishing
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticate ...
scheme to mimic the brand's site, while intercepting passwords which the visitor enters unsuspectingly
*To install drive-by
malware
Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
or revenue generating
adware
Adware, often called advertising-supported software by its developers, is software that generates revenue by automatically displaying Online advertising, online advertisements in the user interface or on a screen presented during the installatio ...
onto the visitors' devices
*To harvest misaddressed e-mail messages mistakenly sent to the typo domain
*To express an opinion that is different from the intended website's opinion
*By legitimate site owners, to block malevolent use of the typo domain by others
*To annoy users of the intended site
Examples
Many companies, including
Verizon
Verizon Communications Inc. ( ), is an American telecommunications company headquartered in New York City. It is the world's second-largest telecommunications company by revenue and its mobile network is the largest wireless carrier in the ...
,
Lufthansa
Deutsche Lufthansa AG (), trading as the Lufthansa Group, is a German aviation group. Its major and founding subsidiary airline Lufthansa German Airlines, branded as Lufthansa, is the flag carrier of Germany. It ranks List of largest airlin ...
, and
Lego
Lego (, ; ; stylised as LEGO) is a line of plastic construction toys manufactured by the Lego Group, a privately held company based in Billund, Denmark. Lego consists of variously coloured interlocking plastic bricks made of acrylonitri ...
, have gained reputations for aggressively chasing down typosquatted names. Lego, for example, has spent roughly on taking 309 cases through
UDRP proceedings.
Celebrities have also pursued their domain names. Prominent examples include basketball player
Dirk Nowitzki's UDRP of DirkSwish.com and actress
Eva Longoria's UDRP of EvaLongoria.org.
Goggle, a typosquatted version of
Google
Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
, was the subject of a 2006 web safety promotion by
McAfee
McAfee Corp. ( ), formerly known as McAfee Associates, Inc. from 1987 to 1997 and 2004 to 2014, Network Associates Inc. from 1997 to 2004, and Intel Security Group from 2014 to 2017, is an American proprietary software company focused on online ...
, a computer security company, which depicted the significant amounts of malware installed through
drive-by downloads upon accessing the site at the time. Goggle installed
SpySheriff. Later, the URL was redirected to google.com; a 2018 check revealed it to redirect users to
adware
Adware, often called advertising-supported software by its developers, is software that generates revenue by automatically displaying Online advertising, online advertisements in the user interface or on a screen presented during the installatio ...
pages, and a 2020 attempt to access the site through a private
DNS resolver hosted by
AdGuard resulted in the page being identified as
malware
Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
and blocked for the user's
security. By mid-2022, it had been turned into a political blog. As of April 2025, goggle.com is not operational.
Another example of corporate typosquatting is yuube.com, targeting
YouTube
YouTube is an American social media and online video sharing platform owned by Google. YouTube was founded on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim who were three former employees of PayPal. Headquartered in ...
users by programming that URL to
redirect
Redirect and its variants (e.g., redirection) may refer to:
Arts, entertainment, and media
* Redirect (album), ''Redirect'' (album), 2012 Christian metal album and its title track by Your Memorial
* Redirected (film), ''Redirected'' (film), a 20 ...
to a malicious website or page that asks users to add a malware "security check extension". Similarly, www.airfrance.com has been typosquatted by www.arifrance.com, diverting users to a website peddling discount travel (although it now redirects to a warning from
Air France
Air France (; legally ''Société Air France, S.A.''), stylised as AIRFRANCE, is the flag carrier of France, and is headquartered in Tremblay-en-France. The airline is a subsidiary of the Air France-KLM Group and is one of the founding members ...
about malware).
Other examples are equifacks.com (
Equifax
Equifax Inc. is an American multinational consumer credit reporting agency headquartered in Atlanta, Atlanta, Georgia and is one of the three largest consumer credit reporting agency, consumer credit reporting agencies, along with Experian and T ...
.com), experianne.com (
Experian
Experian plc is a multinational corporation, multinational data broker and consumer credit reporting company headquartered in Dublin, Ireland. Experian collects and aggregates information on more than 1 billion people and businesses including ...
.com), and tramsonion.com (
TransUnion
TransUnion LLC is an American consumer credit reporting agency. TransUnion collects and aggregates information on over one billion individual consumers in over thirty countries including "200 million files profiling nearly every credit-active co ...
.com); these three typosquatted sites were registered by comedian
John Oliver for his show ''
Last Week Tonight''. Over 550 typosquats related to the
2020 U.S. presidential election were detected in 2019.
The Magniber
ransomware
Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
is being distributed in a typosquatting method that exploits typos made when entering domains, targeting mainly Chrome and Edge users.
In United States law
In the United States, the 1999
Anticybersquatting Consumer Protection Act (ACPA) contains a clause (Section 3(a), amending 15 USC 1117 to include sub-section (d)(2)(B)(ii)) aimed at combatting typosquatting.
On April 17, 2006, evangelist
Jerry Falwell
Jerry Laymon Falwell Sr. (August 11, 1933 – May 15, 2007) was an American Baptist pastor, televangelist, and conservatism in the United States, conservative activist. He was the founding pastor of the Thomas Road Baptist Church, a megachurch ...
failed to get the
U.S Supreme Court to review a decision allowing Christopher Lamparello to use www.fallwell.com. Relying on a plausible misspelling of Falwell's name, Lamparello's
gripe site presents misdirected visitors with scriptural references that are intended to counter the fundamentalist preacher's scathing rebukes against
homosexuality
Homosexuality is romantic attraction, sexual attraction, or Human sexual activity, sexual behavior between people of the same sex or gender. As a sexual orientation, homosexuality is "an enduring pattern of emotional, romantic, and/or sexu ...
. In ''
Lamparello v. Falwell'', the high court let stand a 2005
Fourth Circuit
The United States Court of Appeals for the Fourth Circuit (in case citations, 4th Cir.) is a federal court located in Richmond, Virginia, with appellate jurisdiction over the district courts in the following districts:
* District of Maryland ...
opinion that "the use of a mark in a domain name for a gripe site criticizing the markholder does not constitute cybersquatting."
WIPO resolution procedure
Under the
Uniform Domain-Name Dispute-Resolution Policy (UDRP),
trademark
A trademark (also written trade mark or trade-mark) is a form of intellectual property that consists of a word, phrase, symbol, design, or a combination that identifies a Good (economics and accounting), product or Service (economics), service f ...
holders can file a case at the
World Intellectual Property Organization
The World Intellectual Property Organization (WIPO; (OMPI)) is one of the 15 specialized agencies of the United Nations (UN). Pursuant to the 1967 Convention Establishing the World Intellectual Property Organization, WIPO was created to pr ...
(WIPO) against typosquatters (as with cybersquatters in general).
[ The complainant has to show that the registered domain name is identical or confusingly similar to their trademark, that the registrant has no legitimate interest in the domain name, and that the domain name is being used in bad faith.][
]
See also
* Bitsquatting
* (DNS)
** Domain name spoofing – Phishing attacks that depend on falsifying or misrepresenting an internet domain name
**
**
* – Similar attacks on vanity phonewords
*
*
*
*
References
External links
* (reporting research by Ben Edelman and Tyler Moore
Measuring Typosquatting Perpetrators and Funders
*
{{Domain parking
Cybercrime
Network addressing
Nonstandard spelling
Trademark law
URL