• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 304-800 | Support: +49 5251 304-636
NoSpamProxy
  • PRODUCT
    • NoSpamProxy Cloud
    • NoSpamProxy Protection
    • NoSpamProxy Encryption
    • NoSpamProxy Large Files
    • NoSpamProxy Disclaimer
  • SOLUTIONS
    • M365 Mail Security
    • Managed Certificates
    • 32Guards
    • AS4
  • RESOURCES
    • Documentation
    • Forum
    • Webcast Training
    • Training Courses
    • Support
    • Software Download
  • PARTNERS
    • Finding Resellers
    • Becoming Reseller
    • Partner Portal
    • NFR Licenses
  • COMPANY
    • Contact
    • Testimonials
    • Team
    • Career
    • Events
    • Awards
  • PRICES
  • BLOG
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Was ist Typosquatting?

What is Typosquatting?

Stefan Feist | Technischer Redakteur
Author: Stefan FeistTechnical Writerhttps://www.linkedin.com/in/stefan-feist-23b257b0/–Connect on LinkedIn

Spelling is important, not only at school, but also online. While the only penalty is a point deduction in the exam, a spelling mistake when typing a URL can lead you to a fake website and turn you into a victim of a phishing attack. The criminal technique behind this is called typosquatting. Read our blog article to find out exactly what typosquatting is and how you can protect yourself.

14.08.2024|Last edited:14.08.2024

Typosquatting is a form of computer crime in which attackers deliberately register domain names that resemble well-known websites but contain small typos. It is therefore a sub-category of domain spoofing and is also related to so-called homoglyphic attacks. The aim is to lure Internet users who mistype a web address to the fake website. Typosquatting is also known as URL hijacking, domain mimicry or URL spoofing.

Typosquatting examples

Some examples of what typosquatting can look like:

  • Omitted letters: outloo.de
  • Spelling mistakes and typos: netflicks.com
  • Swapped letters: faecbook.de
  • Short name additions: facebooksocial.com
  • Alternative endings (top-level domains): paypal.co
  • Omitted or inserted hyphens: you-tube.com
  • Subdomain squatting: Typosquatting adds a popular domain name as a subdomain to a less popular domain. For example, a typosquatter might register ‘www.google.superfake.com’.

What are the objectives of typosquatters?

Basically, criminals who practise typosquatting want to earn money. To achieve this, they deceive users. The ultimate methods of profiting from deception are numerous:

Phishing and identity theft

One of the main goals of typosquatting is to trick users into entering personal information such as usernames, passwords, credit card numbers or other sensitive data on a fake website. This information can then be misused for identity theft or other criminal offences.

Distribution of malware

Attackers can use fake domains to spread malware. When a user visits the fake website, it can automatically download malware such as viruses, trojans or ransomware that infects the user’s computer.

Generating advertising revenue

In some cases, typosquatting can be used to generate advertising revenue. The fake websites can be flooded with adverts that generate revenue per click or per impression for the attackers. The basis of this model is the high number of users who accidentally end up on the wrong domain.

Gaining a competitive advantage

Sometimes competitors can use typosquatting to redirect visitors from a popular website to their own. In this way, they can intercept potential customers before they reach the actual target page.

Domain hijacking

In some cases, attackers register typosquatted domains with the intention of later selling them to the company concerned. This can even be a case of extortion, where the company is forced to pay a large sum to acquire the domain and protect its brand. Typosquatting domains can damage a company’s reputation by directing users to sites that are harmful to the company itself.

Manipulating search results

The operator uses the traffic on the actual website to redirect it to competitors’ sites and gets paid per click.

Political goals

Political aims can also drive typosquatters: for example, there were at least two addresses on the US president’s website www.whitehouse.gov that were similar to this URL but not part of the president’s official information offering: www.whitehouse.com (formerly a political discussion site) and www.whitehouse.org (a satirical site).

The infamous hacking incident in the 2016 US elections was also attributed in part to typosquatting, highlighting its potential as a tool of political manipulation.

Typosquatting, domainsquatting, cybersquatting

Domainsquatting (also known as cybersquatting) is the deliberate registration of domain names that are very similar to names, trademarks or other protected designations. The aim of this practice is usually to later sell the domain to the rightful owner of the trademark or name at a disproportionately high price. In addition to financial goals, the domain squatter may also be interested in damaging the reputation of the person or company concerned (see above).

While typosquatting uses deliberate typos or variations in the domain to deceive users, domain squatting involves correctly spelled but unauthorised domains that contain well-known names or brands.

How can you protect yourself from typosquatting?

As spelling mistakes are not criminally relevant, it is difficult to protect yourself from typosquatting in this respect. Many companies try to register domains that are similar to their own in order to prevent misuse.

In addition, it is almost impossible to take action against typosquatting, as the perpetrators usually have their servers abroad and continue to operate under a new name a short time later, even if they are banned by a court. Theoretically, it is conceivable to take action against the operators of typosquatting sites, or even against the central registry DENIC. Unfortunately, the situation is often opaque and the logistical and financial effort involved in securing numerous domains or taking legal action is too great, especially for smaller companies.

Protection against typosquatting

As already mentioned, the targets of typosquatting and phishing attacks are similar. The countermeasures and protective measures are also partially identical:

  • Links in unexpected emails

    Do not click any links in unexpected emails.

  • Check link targets

    Check the link targets of anticipated emails before clicking on the links.

  • Use bookmarks

    Use bookmarks to avoid typing errors.

  • Use search engines

    Use a search engine and click on the links in the search results.

  • Caution with attachments

    Be careful with email attachments.

  • Sender reputation

    Check the sender of emails by implementing and using SPF, DKIM, DMARC and ARC. NoSpamProxy not only checks the sender, but also performs a comprehensive check of the Header-FROM, the header of an email.

  • Level of Trust

    With the help of Level of Trust technology, points are awarded on the basis of a number of features, which are used to calculate the trust in a communication partner. NoSpamProxy Protection also scans outbound emails and assigns trust points to the recipients of these emails.

  • Block emails with malicious URLs

    NoSpamProxy analyses emails for malicious URLs using SURBL filters and blocks affected emails.

  • Check URLs

    URL Safeguard enables URLs in inbound emails to be rewritten so that when the user clicks on them, the system checks again whether there are any negative ratings for this URL.

Not yet using NoSpamProxy?

With NoSpamProxy you can reliably protect your company from cyber attacks. Request your free trial version now!

Get your free NoSpamProxy trial now!
  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • Product
  • Tech & Support
  • Events
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • NoSpamProxy Cloud
  • NoSpamProxy Encryption
  • NoSpamProxy Large Files
  • NoSpamProxy Disclaimer
  • Price request
  • Team
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Becoming a reseller
  • Partners
  • Order Certificates
  • Newsletter

Categories

  • All topics
  • News
  • Support
  • Updates
  • Order certificates

Latest News

  • Info Icon
    Limited support hours on Friday, May 16, 202513.05.2025 - 11:35
  • Was ist ein Zero Day Exploit Preview
    What is a Zero-Day Exploit?23.04.2025 - 14:00
  • Info Icon
    UPDATE: New Google email sender guidelines: What you need to do17.04.2025 - 12:00
IMPRINT • EULA • Privacy Policy • • © 2025 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
Link to: The growing Infostealer threat Link to: The growing Infostealer threat The growing Infostealer threatWachsende Bedrohung durch Infostealer Preview Link to: CAA records for S/MIME certificates will be verified from September 2024 Link to: CAA records for S/MIME certificates will be verified from September 2024 Info IconCAA records for S/MIME certificates will be verified from September 2024
Scroll to top Scroll to top Scroll to top