Typosquatting
A domain one character from yours is not a coincidence. When it has a mail server configured, it is an attack that has already been prepared.
- No Login
- No Software
- No Network Access
- Public Records Only
Read the way an outsider would, from records that are already public.
What Typosquatting Is
Typosquatting is registering a domain that closely resembles a real one, relying on a reader not noticing the difference. A doubled letter, a missing letter, a swapped pair, or a different ending are the usual forms.
The technique is old and was originally about traffic: catch people who mistype a web address and show them advertising. The version that matters to a business now is quieter and considerably more expensive.
A Domain One Character From Yours
In an address bar, at a glance, the substituted character is invisible. That is the entire mechanism.
- smithdental.comYours
- Registered by youYes
- Sends your invoicesYes
- smithdentai.coml changed to i
- RegisteredYes
- Resolves to a live hostYes
- Configured to receive mailYes
- RiskInvoice impersonation
The Forms It Takes
Character Substitution
Replacing a character with one that resembles it.
Omission and Doubling
Dropping a letter or repeating one. These rely on genuine typing errors rather than on careful inspection failing.
Transposition
Swapping adjacent characters. Particularly effective because a reader recognizes the word shape and does not read the letters in order.
Alternate Endings
The same name under a different ending.
Which Lookalikes Actually Matter
The Signal That Actually Matters
Lookalike domains are registered constantly, and most are harmless or speculative.
What a Lookalike Is Used For
The common use is invoice fraud. A message arrives from a domain one character off, referencing a real project, requesting payment to a new account.
What Can Be Done
Registering every variation is impossible and vendors selling that approach are selling an endless subscription.
Lookalikes Among Everything Else
A registered lookalike matters more when the rest of the surface is weak, so it is reported in context.
Common Questions
Registering a handful of the most plausible variants is cheap and reasonable. Attempting to register all of them is not achievable, since the space of near-misses is effectively unlimited.
Sometimes, through the registrar or a UDRP complaint, particularly where a trademark is involved. It takes time and the registrant can usually register another. Worth pursuing for a domain actively being used against you, not as a general strategy.
No. DMARC protects your exact domain. A lookalike is a different domain with its own valid records, and it will pass every authentication check because it is legitimately sending as itself.
Blindspot detects lookalike domains by reading public records only, specifically public DNS. It is not a penetration test, does not contact the lookalike domain, and does not attempt anything against it. Nothing is logged into, no password is tested, and no network is touched.
Check for Armed Lookalikes
The scan reports lookalike domains with a live mail server, which is the form that matters.
We only read public records. We never touch your computers and we never ask for a password.
Keep Reading
Three places this leads next, depending on what you want to do about it.
- Free ToolHow to Stop Email SpoofingEmail spoofing is stopped with three DNS records, not with software. Here is what spoofing actually is, why filters cannot catch it, and the exact steps that block someone sending mail as your company.
- Deep DiveExternal Attack Surface ManagementExternal attack surface management is the continuous discovery of everything about your business that can be reached or read from outside it. Here is what it covers, why traditional security misses it, and the tools that measure it.
- ExplainerEmail SpoofingEmail spoofing forges the sender address on a message. Here is how spoofing an email actually works, why the protocol allows it, how to tell a spoofed email, and what stops it.