Typosquatting means registering a domain that looks like a real brand’s domain, but contains a tiny mistake. It targets users who mistype, skim, or trust what looks familiar. Phishing is the broader trick: it tries to steal passwords, payment details, or confidential data through fake messages, sites, forms, or calls. The two often work together, which is why domain-based attacks are so annoying and so effective.
TLDR: Typosquatting is about deceptive domain names, such as paypa1.com instead of paypal.com. Phishing is the scam method that may use that fake domain to steal login details. In one user case, an employee types a vendor URL too fast, lands on a fake invoice portal, and enters credentials in under 30 seconds. If only 2% of 5,000 employees make that mistake once a year, that is 100 chances for attackers to get in.
What Is Typosquatting?
Typosquatting, also called URL hijacking, is the practice of registering web addresses that are close to trusted domain names. Attackers count on small human errors. One wrong letter can send a person to a malicious site.
Common typosquatting tricks include:
- Misspellings: goggle.com instead of google.com
- Extra letters: amazoon.com instead of amazon.com
- Missing letters: microsft.com instead of microsoft.com
- Swapped letters: faecbook.com instead of facebook.com
- Lookalike characters: paypa1.com using the number 1 instead of the letter l
- Wrong domain endings: brand.co instead of brand.com
The fake site may show ads, serve malware, imitate a login page, or redirect users elsewhere. Sometimes the page does almost nothing. That can still help attackers measure traffic and decide if the domain is worth turning into a larger scam.
What Is Phishing?
Phishing is a social engineering attack. The attacker pretends to be someone trusted and pushes the victim to act. That action might be clicking a link, entering a password, opening an attachment, approving a payment, or sharing a one time code.
Phishing can arrive through:
- Email messages that look like bank alerts
- Text messages about missed deliveries
- Fake login pages for cloud tools
- QR codes on posters or receipts
- Voice calls from fake support agents
- Direct messages on work chat apps
Phishing does not always need a typo domain. A scammer might use a hacked real account, a shortened link, or an attachment. Still, a convincing fake domain makes phishing much stronger. It gives the scam a place to happen.
Typosquatting vs Phishing: The Core Difference
The simplest way to separate them is this: typosquatting is the fake address; phishing is the trick played through it.
Think of typosquatting as the counterfeit storefront. Phishing is the salesperson inside asking for your card number.
| Attack Type | Main Focus | Typical Goal |
|---|---|---|
| Typosquatting | Fake or misspelled domain names | Capture mistaken visitors or build trust |
| Phishing | Deceptive messages, pages, or requests | Steal data, money, or access |
The overlap is where things get risky. A phishing email sent from support@micros0ft-billing.com may look credible during a busy morning. Honestly, it feels like attackers design these scams for the exact moment when someone has eight tabs open and 14 unread messages.
How a Domain-Based Attack Works
A typical typosquatting phishing attack follows a clear path:
- Domain selection: The attacker finds a brand people trust.
- Registration: They buy a similar domain with a typo or lookalike character.
- Site creation: They clone a login page or payment page.
- Traffic bait: They send emails, ads, texts, or wait for typing mistakes.
- Credential theft: The victim enters data into the fake site.
- Account misuse: The attacker logs in, changes settings, steals files, or sends more scams.
Some attacks are fast. A fake page can collect credentials and redirect the victim to the real site. The user may think the first login failed. That little delay can hide the entire theft.
Why Typosquatting Still Works
Typosquatting survives because people are busy, screens are small, and domain names are easy to fake at a glance. Mobile browsers often hide the full URL. Email clients may display a sender name instead of the real address. That is plenty of room for trouble.
Attackers also use internationalized domain names. These allow letters from other alphabets. Some characters look nearly identical to Latin letters. For example, a Cyrillic “а” can appear like a regular “a” to many users. That makes visual checks harder.
It drives me crazy that some security tools still show weak warnings, or bury them behind tiny icons. If a browser takes five seconds longer to load a suspicious site but gives no useful warning, the user may blame the network and keep going.
Common Signs of Typosquatting
Watch for these warning signs before entering passwords or payment details:
- Odd spelling: One missing, extra, or swapped character
- Strange domain ending: A familiar company using an unfamiliar extension
- Unexpected login prompts: Especially after clicking from email
- Poor page quality: Broken images, awkward wording, or outdated branding
- Urgent language: “Act now,” “account locked,” or “payment failed”
- Certificate confusion: A padlock only proves encryption, not trust
The padlock point matters. Many fake sites use HTTPS. A secure connection to a scam site is still a scam.
Business Risks From Fake Domains
For companies, typosquatting is not only a user problem. It can damage brand trust, steal customer credentials, divert payments, and expose staff accounts. A fake supplier portal can lead to invoice fraud. A fake HR portal can harvest tax details. A fake software update page can spread malware.
Large brands may face thousands of lookalike domains. Smaller companies are not safe either. In fact, attackers may prefer them because monitoring is weaker and takedowns are slower.
How Users Can Protect Themselves
- Use bookmarks for banking, work tools, and shopping sites.
- Check the domain from right to left. The real registered domain is just before the final extension.
- Avoid logging in from email links unless you expected the message.
- Use a password manager. It may refuse to autofill on fake domains.
- Turn on multi-factor authentication, preferably with an authenticator app or hardware key.
- Report suspicious sites to your security team, browser provider, or hosting company.
How Organizations Can Reduce Risk
Companies need a mix of prevention, detection, and response. No single control catches every fake domain.
- Register obvious typo domains for high-value brands and portals.
- Use domain monitoring to spot new lookalike registrations.
- Set up SPF, DKIM, and DMARC to reduce email spoofing.
- Train staff with real examples, not generic slides.
- Use single sign-on and hardware security keys for critical systems.
- Create a takedown process before an incident occurs.
The best training is specific. Show employees domains that look like your real ones. Ask them to spot the difference. Five minutes of practical testing beats a 45-minute lecture that everyone clicks through while answering email.
The Bottom Line
Typosquatting and phishing are different, but they often appear as a pair. Typosquatting supplies the fake domain. Phishing supplies the pressure, story, and request. If a message makes you hurry, pay, reset, verify, or download, slow down and inspect the domain with care.
Small spelling errors can create big security incidents. A single wrong character in a URL can put credentials, money, and customer trust at risk. Treat domains as security signals, not background text.




