▸ Typosquatting checker
Type a brand or a domain. We generate thousands of lookalike permutations across nine classes, including the sound-alike spellings a keyboard map never reaches, and check every one against our index of registered domains.
Typosquatting is registering a domain that looks like somebody else's: one letter dropped, two letters swapped, a 1 where an l belongs, or the same name in a different TLD. The registration costs a few dollars, the visitor who mistyped never notices, and the traffic is worth money to whoever holds it. This free typosquatting checker takes a brand, generates every plausible lookalike, and tells you which ones somebody has already taken.
We answer from a local index of hundreds of millions of registered domains instead of resolving DNS one name at a time, which is why a full sweep comes back in milliseconds rather than minutes and why we can run thousands of variants instead of a few hundred. Every name on the result list is a domain somebody has already registered. The list is the answer: read it, and the ones sitting closest to your own name are the ones worth an afternoon.
▸ The nine permutation classes
Every candidate is tagged with the transformation that produced it, so you can look at homoglyphs alone, or at nothing but the TLD sweep across 160 zones.
01 ▸ Omission
Each character in turn is deleted. The most productive class there is, because a dropped letter is the typo people make without looking at the screen.
nike.com -> nke.com
02 ▸ Insertion
A keyboard-adjacent character is inserted beside each position. Adjacency is the point: a finger lands on the next key over, not on a random letter.
nike.com -> nikje.com
03 ▸ Substitution
Each character is replaced by one of its QWERTY neighbours. This is the mistake you make when your whole hand is one key off.
nike.com -> mike.com
04 ▸ Phonetic
Spellings that sound the same are swapped: c for k, f for ph, y for i, u for oo. QWERTY never puts c next to k and neither shape resembles the other, so this is the class an adjacency-only generator cannot see - and it is where names like boocing.com live.
nike.com -> nice.com
05 ▸ Transposition
Adjacent characters are swapped. Fast typists produce these constantly, which is why they are among the most valuable names to squat.
nike.com -> nkie.com
06 ▸ Duplication
A character is repeated. Key repeat, a bouncy switch and a hesitant finger all land in the same place.
nike.com -> nikee.com
07 ▸ Homoglyph
Characters that share a shape are swapped: l for 1, o for 0, rn for m, vv for w, cl for d. Nobody types these by accident, they are read straight past.
nike.com -> n1ke.com
08 ▸ Affix and hyphenation
A hyphen is inserted at each position, and a wordlist of service nouns is attached front and back. This is combosquatting: nobody mistypes it, they trust it.
nike.com -> nike-login.com
09 ▸ TLD sweep
The exact brand across a ranked list of generic TLDs, ccTLDs and the cheap zones that dominate abuse reporting. Same spelling, different zone.
nike.com -> nike.tk
Duplicates across classes are dropped, and the brand you typed is never returned as its own lookalike. One lookup is capped at 2,500 candidates, and the tool says so on screen when the cap binds rather than truncating in silence.
▸ Try it on a brand
▸ How to triage a hit
Any recognisable brand has hundreds of registered lookalikes and most of them are noise. Four things in the list itself separate the ones worth your afternoon.
Distance from your name
One dropped letter or one swapped pair is a name people reach by accident. Three edits away is a name nobody types by mistake, and it is only worth your time if somebody chose it on purpose. Start at the top of the list and stop when the names stop looking like yours.
The permutation class
The class column says which mistake produced the name. A transposition is something a fast typist does to themselves. A homoglyph, a phonetic respelling or a hyphenated service word is something a person chose, and the choosing is the part that should worry you.
Which TLD it sits in
Your own name in .com or in your country code is usually a defensive registration, quite possibly your own. The same name in one of the cheap or free zones that dominate abuse reporting was not bought by a brand protection team.
Plausibility
Read the name out loud. A homoglyph or a hyphenated service word aimed squarely at your login page is a different problem from a two-letter transposition somebody has been parking since 2014.
▸ What to do about one
In rough order of effort, and of how sure you need to be before you start.
- 01 Capture the evidenceExport the row, note the domain and the date you found it, and take your own screenshot of whatever it serves. Evidence disappears the moment the operator notices they have been found.
- 02 Registrar and host abuseThe fastest route is almost always the registrar's or the hosting provider's abuse contact, with your own screenshot as evidence that the name is in active use. Live phishing gets acted on in hours; a parked name usually gets nothing.
- 03 UDRP or the local equivalentWhere a name is used in bad faith against a mark you own, a UDRP complaint transfers it to you. It costs money and takes weeks, so it is for the names that matter rather than for a long tail.
- 04 Defensive registrationFor the handful of variants closest to your own name, buying them is cheaper than any of the above. Filter the table to available and you have exactly that shopping list.
The long version, including dnstwist, wildcard corpus search and how to work Certificate Transparency directly, is in the guide: How to find typosquatting domains
▸ What this is not
- We do not resolve DNS live. Every answer comes out of our index of registered domains, zone-file snapshots and Certificate Transparency. A name can be registered and have no A record, and this tool will still show it as registered.
- We do not fetch or screenshot the site. We tell you the name is registered. Whether there is a phishing page behind it, a parking placeholder or nothing at all is something you have to go and look at yourself.
- We do not judge intent. Many lookalikes are defensive registrations by the brand itself, and a two-letter overlap with your name is not evidence of anything. The tool reports what is registered; the reading is yours.
- ASCII only, no punycode. Cyrillic and Greek confusables are where the most dangerous lookalikes live, and this version does not cover them. Search the index for
xn--names alongside this if that is your threat model.
▸ Questions people actually ask
? What is typosquatting?
Typosquatting is registering a domain that closely resembles somebody else's, so that people who mistype the real one land on yours instead. The variants come from a small set of mechanical transformations: a dropped letter, a swapped pair, a keyboard-adjacent slip, a character that looks like another, a spelling that sounds the same, or the same name in a different TLD.
? How do I check if someone registered a domain similar to mine?
Type your brand into the checker at the top of this page. It generates up to 2,500 lookalike variants across nine permutation classes plus a sweep of 160 TLDs, looks every one of them up in our index of registered domains, and returns the ones somebody already holds.
? Is typosquatting illegal?
That depends on use rather than on registration. Registering a misspelling is not by itself unlawful in most jurisdictions, but using it in bad faith against a trademark you do not own is actionable under the UDRP and, in the United States, under the ACPA. A parked misspelling and a live credential-harvesting page are treated very differently.
? What is the difference between typosquatting and cybersquatting?
Cybersquatting is the broad term for registering a domain in bad faith against somebody else's mark, usually to resell it. Typosquatting is the subset that targets typing mistakes rather than the name itself. Combosquatting is a third variant that adds a word instead of changing one: your brand plus login, secure or pay.
? How do I know whether a lookalike domain is actually dangerous?
Registration on its own tells you very little: most lookalikes of a large brand are parked, and plenty are the brand’s own defensive holdings. What matters is whether somebody chose the name rather than stumbled into it, and what is behind it today. Take the handful nearest your own name, open them, and check where they resolve, whether they serve a login form and whether they accept mail. That last step is deliberately not automated here.
? How do I report a typosquatted domain?
Start with the abuse contact at the registrar and the hosting provider, attaching a screenshot you took yourself and the date you found the name. If the name is being used in bad faith against a mark you own, a UDRP complaint through WIPO can transfer it to you. Capture your evidence before you file, because it tends to vanish.
? Is this a free dnstwist alternative?
It covers the same permutation classes as dnstwist, plus a phonetic class dnstwist does not have, and runs them in a browser with no install, no signup and no API key. The difference is the data underneath: instead of resolving each variant over live DNS, we answer from a local index, which is why a full sweep returns in milliseconds and why we can run thousands of variants instead of a few hundred.