Domain name security, theft, recovery and disputes
Abstract pulse line illustration representing Typosquatting

StatusTime-critical

Typosquatting

Governing policy
ICANN UDRP Paragraph 4(a); URS Procedure
Window
URS response: 14 calendar days
Authority
URS Procedure, page version 21 February 2024, effective 21 August 2025

Misspelled domains registered in bulk and monetized while they resolve, answered by speed rather than by process

What typosquatting is, and why the clock rules it

Typosquatting is the registration of domain names that are deliberate misspellings of a well-known name — a doubled letter, a dropped letter, a keyboard neighbor swapped in — so that traffic from people who mistype the real address arrives somewhere the squatter controls. Legally it is cybersquatting. Operationally it is cybersquatting with a mechanical generation step bolted on the front, which changes almost everything about how it is handled.

I classify it as time-critical rather than simply disputed, and the reason is practical rather than doctrinal. Typosquats are registered in bulk and monetized while they resolve. Phishing pages, credential harvesting, malware delivery and advertising revenue all accrue by the hour. A dispute proceeding measured in weeks does not stop any of it. The working response is takedown with the host and registrar, blocking at the resolver and in mail filtering, and suspension — with the question of who ends up owning the string, if it matters at all, handled afterward.

How the variant space is generated

Generation is mechanical. An attacker enumerates variants of a target string, checks availability, and registers whatever is free, frequently across many TLDs in one pass. The transformation classes documented in the research literature and reflected in panel practice are:

  • Adjacent-key substitution — a letter replaced by its keyboard neighbor.
  • Character omission — a letter dropped.
  • Character duplication — a letter typed twice.
  • Transposition or inversion — two adjacent letters swapped.
  • Visually similar charactersrn standing in for m, 1 for l, 0 for O, along with accented forms and homoglyphs (a homoglyph is a character that renders like another, such as a Cyrillic "а" that looks identical to a Latin "a").
  • TLD substitution — the exact string, a different extension.

A defensive-registration program that covers the exact string in .com and nothing else misses most of that space. Enumerating the variants with the same transformations an attacker uses, and monitoring them continuously, is the approach that holds up. Buying a static handful of names is the approach that feels like coverage and is not.

How a typosquat makes money

The largest longitudinal measurement of the phenomenon sorted typosquat monetization into a small number of recurring categories, and they have proved durable:

  • Ad parking — domain parking means pointing the name at an auto-generated page of advertisements that pays the holder per click.
  • Affiliate abuse — redirecting the visitor onward to the real site through an affiliate link, so the squatter earns commission on a sale they did nothing to generate.
  • Scam pages — surveys, prize offers and malware distribution.
  • Hit stealing — sending the mistyped traffic to a competitor of the target, usually for a referral fee.
  • Adult content — traffic monetized on its own terms.
  • For-sale listings — the name parked with a price on it.

The category matters because it determines what the evidence looks like. An affiliate redirect proves commercial gain in a way a blank page never will, and a page carrying the target's own logo goes to likelihood of confusion directly. What the domain was doing, at the time it was doing it, is the record.

What the UDRP does with a misspelling

Typosquatting is not a separate cause of action. It is prosecuted as cybersquatting, through the same three-element test at Paragraph 4(a) of the UDRP: confusing similarity to a mark in which the complainant has rights, no rights or legitimate interests in the registrant, and registration and use in bad faith.

On the first element, the WIPO Jurisprudential Overview 3.0 — a synthesis of consensus panel views published in 2017, superseding the 2011 edition, and not itself an ICANN consensus policy — records at section 1.9 that a domain consisting of a common, obvious or intentional misspelling of a trademark is considered confusingly similar to that mark. The examples it gives are the same transformation classes above: adjacent keyboard substitutions, similar-looking characters, accented variants and character inversions. On the second and third elements, panels have treated an intentional misspelling as itself indicating an intent to deceive users who were looking for the complainant.

Under United States law, the bulk pattern does specific work. The ACPA's non-exclusive bad-faith factors include the registration of multiple domain names that the registrant knows are identical or confusingly similar to others' distinctive marks, or dilutive of famous marks. Documenting the portfolio, rather than the single name in front of you, is what engages it.

The URS: suspension, a short clock, and a word limit

Uniform Rapid Suspension exists because the ordinary dispute timetable is too slow for exactly this problem. It is a fast track for clear-cut cases, decided on a higher evidentiary standard than the UDRP, and it produces suspension rather than transfer: the domain is suspended for the balance of the registration period and its nameservers redirect to an informational page, with the registration record otherwise unchanged.

The URS Procedure sets the constraints. A response is due within 14 calendar days of the Notice of Complaint. A respondent who defaults may seek de novo review — a fresh determination of the whole matter rather than an error review — for up to six months after the Default notice, extendable by six more. Appeals run 14 days from a Default or Final Determination. And the complaint itself is capped at 500 words of explanatory text, which is a genuine constraint when the subject is a portfolio of dozens of variants rather than one name.

Section 11 penalizes abuse on a counted schedule: two abusive complaints bring a one-year bar on filing, one deliberate material falsehood brings a one-year bar, and two deliberate material falsehoods bring a permanent bar. Overstating a record under a 500-word limit is a poor trade.

Evidence, and why MX records matter

Preserve the evidence while the site still resolves. Typosquats are taken down, reconfigured and re-parked constantly, and the Paragraph 4(b)(iv) showing — that the registrant intentionally attempted to attract users for commercial gain by creating a likelihood of confusion — depends entirely on what the domain was doing at the time. Full-page captures with timestamps, the complete redirect chain rather than just the landing URL, the DNS records as served, and the Whois or RDAP record as it stood.

Check the MX records specifically. An MX record is the DNS record naming the mail server for a domain, and a typosquat configured to receive mail is usually not there for web traffic at all. That configuration points at business email compromise: intercepting messages sent to a mistyped address, or sending messages from one. It is a materially different threat from a parked ad page and it warrants a materially faster response.

On procedure, the Rules contemplate a complaint covering multiple domain names where the same holder is involved. Filing one proceeding per name against a bulk registrant multiplies cost and effort for no gain.

A documented pattern: the CISA advisory

For a concrete example of typosquatting operating at scale as an attack technique rather than a monetization scheme, the joint cybersecurity advisory AA23-025A, issued 25 January 2023, describes activity that CISA characterized as part of a widespread, financially motivated phishing campaign and related to malicious typosquatting.

The pattern is instructive. First-stage domain names followed naming conventions themed around IT help and support — the advisory names hservice[.]live, gscare[.]live and nhelpcare[.]info, with myhelpcare[.]online, myhelpcare[.]cc and win03[.]xyz also observed. Brands impersonated in the campaign included Norton, GeekSupport, Geek Squad, Amazon, Microsoft, McAfee and PayPal. Delivery ran both ways: direct phishing links, and callback phishing, where the email prompts the recipient to telephone the attacker, who then steers them to the first-stage domain by voice.

Note what a UDRP would have achieved against that infrastructure on its own timetable. The names were disposable. Detection, blocking and takedown are the controls that matter against this shape of campaign; the dispute process cleans up afterward, if at all.

Where this needs counsel, and where it does not

Two different problems live under one word here, and they take different help. The security response — detection, evidence preservation, resolver and mail blocking, host and registrar takedown — is operational work that a security team can run continuously. The dispute response is not. Whether to file a UDRP, whether a given TLD is within URS scope at all, how to plead a portfolio inside a 500-word limit without straying into what section 11 counts as a material falsehood, and whether a US federal action under the ACPA is available against a particular registrant — these are legal determinations, and they require a trademark attorney experienced in domain disputes.

I will say plainly that registering every possible misspelling is not a strategy. The variant space across omission, duplication, transposition, adjacent keys, homoglyphs and every available extension is far larger than any defensive budget, and the names an attacker will actually use are chosen after the fact. Monitoring the space beats trying to own it. Owning the handful that would do the most damage in an email attack is a reasonable exception, not a program.

Frequently Asked Questions

Is typosquatting illegal?

Typosquatting is not a separate cause of action; it is pursued as cybersquatting. Under the UDRP it runs through the same Paragraph 4(a) test — confusing similarity, no rights or legitimate interests, and registration and use in bad faith — with panels treating a deliberate misspelling as confusingly similar to the mark and as indicating an intent to deceive. In the United States the Anticybersquatting Consumer Protection Act applies, and its bad-faith factors expressly reach the registration of multiple domains known to be others' distinctive marks.

What is the difference between typosquatting and cybersquatting?

Cybersquatting is the broad category: registering or holding a domain matching someone else's trademark in bad faith. Typosquatting is a subset defined by how the string is produced — mechanically, as a deliberate misspelling of a known name, usually in bulk and often across many extensions at once. The legal test is identical. What differs is scale and speed: typosquats are generated by the hundred, monetized while they resolve, and frequently used for phishing, which is why the response is operational before it is procedural.

Does the URS transfer a typosquatted domain to the brand owner?

No. Uniform Rapid Suspension suspends the domain for the balance of its registration period and points the nameservers at an informational page. The registration record is otherwise unchanged and the registrant keeps the name. When the registration period expires, so does the suspension. The URS is fast and narrow by design and fits cases where stopping the domain resolving is the objective. Where the objective is to acquire the name, the UDRP or a court action is the route, and which one to use is a decision for counsel.

Why do MX records on a typosquat matter?

An MX record is the DNS record that names the mail server for a domain. A typosquat with MX records configured is set up to receive email, which usually means the operator is not after mistyped web traffic at all. That configuration is characteristic of business email compromise: intercepting messages addressed to a mistyped domain, or sending messages that appear to come from one. It signals a materially more damaging threat than a parked advertising page, and checking for it should be part of any triage of a newly discovered variant.

Can several typosquatted domains be covered in one UDRP complaint?

The Rules for the UDRP contemplate a complaint covering multiple domain names where the same holder is involved, and consolidating is the normal approach against a bulk registrant. Filing separately for each name multiplies cost and effort without improving the case. Whether a particular set of registrations is properly consolidated — including where registrant details differ but common control can be shown — is an argument that has to be made on the evidence, and how to frame it is a question for the attorney handling the filing.

How should a business protect itself against typosquatting?

The workable posture is monitoring rather than acquisition. Enumerate the variant space using the same transformation classes attackers use — omission, duplication, transposition, adjacent-key substitution, homoglyphs and extension substitution — and watch it continuously, rather than registering a static handful of names and calling it covered. Preserve evidence while a hostile variant still resolves, check its MX records to distinguish an email attack from an advertising page, and route blocking and takedown through security operations while the dispute question goes to counsel.

How quickly can a typosquatted domain be taken offline?

That depends on the route, not on the merits. Host and registrar abuse reporting, resolver blocking and mail filtering can act in hours and do not wait for anyone's determination. The dispute tracks are slower by construction: under the URS a response is due 14 calendar days after the Notice of Complaint, and under the UDRP a respondent has 20 days to respond with a decision due 14 days after the panel is appointed. That gap is precisely why typosquatting is treated as an incident first and a dispute second.
Keep reading

Read the guides

The entries describe what a mechanism is. The guides describe what to do with it, in sequence, and where each route closes.

This is a reference, not a practice. Hartzer.net sells nothing, takes no engagements, and is not legal advice. Nothing here creates any relationship or preserves any deadline.

Top