2026-06-01
Domain typo squatting: small change, real risk

A convincing impersonation domain does not need to look unusual. In many cases, the smaller the difference, the more effective it is.
Domain typo squatting is the practice of registering a lookalike version of a legitimate domain in the hope that people will not notice the change. The domain may be used for phishing emails, fake login pages, payment fraud, or traffic interception. It may also be kept quiet until the right moment arrives.
This is why lookalike-domain monitoring matters: the useful signal is often not a dramatic visual clone, but a tiny change backed by infrastructure that shows intent.
What domain typo squatting looks like
Attackers have several ways to create a domain that feels familiar at a glance. Using our on-labs.net domain as an example, common patterns could include:
- Missing letters:
on-lab.net - Extra letters:
on-labss.net - Adjacent-key substitutions:
on-lavs.net - Transposed letters:
on-lbas.net - Added words or separators:
on-labs-support.net - Lookalike characters:
on-iabs.net, replacing the lowercaselwith anithat may resemble an uppercaseIin some typefaces
The examples are simple, but that is the point. A recipient reading quickly may recognize the shape of a name rather than inspect every character.
Lookalike characters are particularly effective because some typefaces make different characters appear almost identical. A lowercase l and an uppercase I can be easy to confuse. That creates a domain which may survive a quick glance in an inbox, especially on a mobile screen.
Registration is only the first clue
A suspicious registration deserves attention, but the surrounding infrastructure helps determine how urgently it should be treated.
Useful questions include:
- Does the domain have
MXrecords, indicating that it is configured to receive email? - Does it publish other mail-related DNS records?
- Does the website resolve, and where does it lead?
- Is the domain redirecting visitors to the legitimate website?
- Does its behavior change over time?
- Are there related DNS, certificate, or hosting observations that make the domain more concerning?
A redirect to the real website does not make a lookalike domain safe. It may be camouflage. Someone who checks the domain in a browser sees the expected site, while the same domain can still be used in email addresses designed to impersonate a trusted person or organization.
Case study: the single-character switch
While monitoring for a podcaster, Onlooker detected a domain that differed from the podcaster's legitimate domain by only one character: a lowercase l had been swapped for an uppercase I.
That l to I change was visually subtle. Depending on the font, the lookalike could pass as the original during a quick inbox scan.
The domain was not merely registered and parked. It had MX records, showing that email infrastructure had been configured. The domain was being used to send emails, making the visual similarity operationally significant rather than theoretical.
There was another important detail: visiting the suspicious domain redirected the browser to the podcaster's genuine website. To a casual visitor, everything appeared normal. The redirect reduced the chance that someone checking the URL would realize they had landed on an impersonation domain, while the mail setup allowed the lookalike to be used as part of an email-based approach.
Taken together, the signals told a clearer story:
- The domain closely imitated the legitimate brand.
- The difference was hard to spot visually.
MXrecords showed that the domain was mail-enabled.- Emails were being sent from the lookalike domain.
- Web traffic redirected to the genuine site, helping the domain appear harmless when checked.
For privacy and safety, we are not publishing the podcaster's name or either domain. The useful lesson is the pattern: a browser redirect can distract from the more important question of what the domain is equipped to do elsewhere.
How investigation tracking helped
Detection was the start of the work, not the end.
Onlooker's investigation functionality allowed the suspicious domain to be followed after the initial finding. Instead of treating the domain as a single point-in-time alert, the investigation kept the lookalike in view so that follow-up observations could be reviewed together.
That made it easier to track the malicious domain as a developing piece of infrastructure and retain the context that mattered: the original lookalike-domain signal, the mail-related DNS records, and the redirect behavior. Keeping those related observations connected helps an analyst explain why the domain deserves escalation, even when its website appears benign at first glance.
The same workflow is useful beyond this case. A newly registered lookalike may begin as an inactive domain, add mail handling later, change hosting, or start redirecting visitors after registration. Investigation tracking helps turn those changes into a coherent timeline rather than a set of disconnected alerts.
What teams should do next
A practical typo-squatting response starts with a few repeatable steps:
- Monitor important brand, product, and public-facing domains for close variations.
- Review the exact character differences in each suspicious registration.
- Check
MXand other DNS records rather than relying only on the website. - Record redirects and follow them to their final destination.
- Track suspicious domains over time so infrastructure changes remain connected to the original finding.
- Escalate credible impersonation activity quickly, with enough evidence for internal stakeholders and external providers.
The most convincing lookalike domains are often the ones designed to seem unremarkable. A single character can be enough to create risk, and a familiar-looking website can be part of the disguise.
Start monitoring your domains
Onlooker helps teams detect lookalike domains and investigate the signals around them before small changes become bigger problems.
Start your 7-day free trial of Onlooker and begin monitoring your domains today.