TL;DR: Typosquatting uses misspelled or look-alike domains to redirect users to spoofed login pages, ad fraud, malware, or phishing infrastructure, and SecurityScorecard says it scans 4.1 billion IP addresses and domains weekly to surface these threats. The control problem is not just brand abuse, but the gap between human typing errors and domain, email, and DNS governance.
NHIMG editorial — based on content published by SecurityScorecard: Typosquatting: How look-alike domains drive credential theft and brand abuse
Questions worth separating out
Q: What should security teams do first when they find a typosquatted domain?
A: First, confirm whether the domain is parked, redirecting, or hosting a live login or download path.
Q: Why do look-alike domains still succeed against modern security controls?
A: They succeed because the domain itself is technically valid, while the intent behind it is malicious.
Q: How can organisations reduce credential theft from typosquatting?
A: Use phishing-resistant authentication, monitor for look-alike domains, and make unexpected login pages harder to trust through user training and browser or DNS filtering.
Practitioner guidance
- Register common look-alike domains Buy the obvious misspellings, TLD variants, and brand-plus-keyword combinations before attackers do, especially for login and support flows.
- Monitor new registrations and parked domains Use certificate transparency logs, WHOIS, DNS changes, and threat feeds to flag look-alike domains before they are weaponized.
- Harden email authentication Enforce SPF, DKIM, and DMARC so spoofed domains cannot easily deliver mail that appears to come from your organisation or key vendors.
What's in the full article
SecurityScorecard's full article covers the operational detail this post intentionally leaves for the source:
- The full breakdown of typosquatting detection methods using WHOIS, DNS records, certificate transparency logs, and web crawling.
- The article's examples of common domain variants, including misspellings, homoglyphs, TLD swaps, combosquatting, and subdomain spoofing.
- The legal routes for takedown under ACPA and WIPO dispute processes, including when each route is typically used.
- SecurityScorecard's own scanning approach across domains and vendor footprint monitoring, which goes beyond the governance analysis here.
👉 Read SecurityScorecard's analysis of typosquatting, look-alike domains, and credential theft →
Typosquatting and look-alike domains: what security teams miss?
Explore further
Typosquatting is an identity assurance problem, not just a domain abuse problem. A look-alike domain only becomes dangerous when a user, browser, or email control treats it as trustworthy enough to proceed. That means the real control gap sits between human recognition and identity validation, where MFA, federated login, and domain reputation all intersect. Security teams should treat typosquatting as a login-path integrity issue, not a brand-only nuisance.
A question worth separating out:
Q: How should companies balance legal takedowns with technical controls?
A: Treat takedown as one layer, not the control strategy. Legal action can remove a domain, but monitoring, email authentication, identity controls, and rapid escalation are what limit exposure before the domain is removed.
👉 Read our full editorial: Typosquatting turns mistyped domains into credential theft paths