Skip to main content
Brand Security Updated

Typosquatting: How It Works and How to Respond

What typosquatting is, the patterns it follows, how often it happens to Shopify stores, and how to respond with evidence.

What is typosquatting?

Typosquatting is the practice of registering a domain that closely resembles a real one, so that people who mistype an address or misread a link arrive somewhere the brand does not control. If a store runs on coolsneakers.com, a typosquatter might register coolsneaker.com, coolsneekers.com, or coolsneakers.co.

The name is only the first half. A registration on its own is not proof of fraud — plenty of close domains are parked, unrelated, or owned by the brand itself. What matters is where a visitor ends up. Record the page that loads, any redirect it follows, and whether the visitor is asked for a password or a payment.

Typosquatting is one pattern inside a wider family of lookalike domains. The others are covered below.

What does typosquatting look like in practice?

Typosquats follow a small number of predictable patterns, because they exploit predictable mistakes. Each row below assumes a real domain of coolsneakers.com.

PatternTyposquatThe mistake it captures
Omitted charactercoolsneaker.comA dropped letter at the end of a word
Doubled charactercoolssneakers.comA key held a moment too long
Transpositioncoolsnaekers.comTwo adjacent letters swapped
Adjacent keycoolsneskers.comA finger landing one key over
Similar glyphc00lsneakers.comA number read as a letter
Alternate endingcoolsneakers.coA truncated or guessed extension

Two related patterns are usually grouped with typosquatting but work differently:

  • Homograph attacks substitute characters from other alphabets that render almost identically — a Cyrillic а for a Latin a. The address can look exact rather than merely close.
  • Combosquatting adds a plausible word instead of changing a letter: coolsneakers-official.com, shop-coolsneakers.com. Nothing is misspelled, so spell-checking and typo generation both miss it.

How common is typosquatting for Shopify stores?

More common than most merchants expect, and most of it is quiet rather than obviously malicious.

The 2026 Shopify Brand Protection Report (edition 2026.7) scanned 2,000 leading Shopify stores on 4 June 2026 and rescanned them 61 days later, using registry creation dates to confirm which domains were genuinely new. Across the 1,991 stores present in both waves:

  • 581 new lookalike domains were registered in 61 days — about 9.5 per day, or one every 2.5 hours.
  • 32.5% of stores gained at least one new lookalike inside that window.
  • Roughly 89% of registered lookalikes resolved to nothing at all.

That last number is the one that misleads people. To test whether “resolves to nothing” meant “harmless,” the study requested a random sample of 2,000 dormant lookalikes directly. Of those, 71.8% responded and 2.9% returned a live Shopify storefront — a sampled estimate carrying about ±0.7 points at 95% confidence. Around half of those were the brands’ own regional stores. The rest were likely clones, including plain typosquats that no public blocklist had flagged.

Two things follow. Dormant is a snapshot, not a verdict: a parked domain can activate later. And blocklists are a floor rather than a count, because they need time to notice a new domain and no single list sees every campaign.

Why do typosquatters target Shopify stores?

Because the traffic is valuable, the trust is borrowed, and the setup cost is close to nothing.

  • The visitor is already buying. Someone typing a store’s address by hand has decided to shop. A typosquat intercepts demand at its most valuable moment.
  • The brand supplies the credibility. A fake storefront does not need to earn trust. It inherits it from the name in the address bar.
  • The economics are lopsided. A domain costs about $12. One deceived order can exceed that many times over.
  • Storefront assets are public by design. Product photography, descriptions, and layout can be lifted quickly, and the result looks convincing because it largely is a copy.

What does a typosquatted domain actually cost you?

The direct loss is rarely the largest one.

CostHow it shows up
Diverted ordersA customer completes a purchase somewhere else and you never see the session
Support loadYour team fields tickets about orders you have no record of
Reputation damageA customer defrauded on a lookalike blames the brand in the address, which is you
Wasted acquisition spendPaid traffic for your brand terms lands on someone else’s checkout
Deliverability harmImpersonation from adjacent domains can affect how your real mail is treated

The reputation cost is the one merchants underestimate. A customer who cannot tell which store was real does not conclude that they were careless. They conclude that the brand is unsafe.

How is typosquatting different from cybersquatting?

The difference is intent, and it changes which remedy applies.

Typosquatting targets the mistake. The registrant wants the traffic that lands on a misspelling, and the value is in the accidental visit.

Cybersquatting targets the name. The registrant holds a domain matching a mark, usually to resell it to the brand or to trade on its reputation. The value is in the name itself.

The categories overlap, and one domain can be both. The distinction matters when you choose a route: a bad-faith registration of your mark is the stronger case under trademark process, while a deceptive page is better reported as abuse or phishing based on what it actually does.

Is typosquatting illegal?

Sometimes, and it depends on the mark, the conduct, and the jurisdiction. Registering a misspelled domain is not automatically unlawful.

Two routes come up most often:

  • The UDRP, an arbitration process run through the registrar, can transfer or cancel a domain. It requires proof of three things together: the domain is confusingly similar to your mark, the registrant has no legitimate interest in it, and the registration and use were in bad faith. It awards no damages.
  • Trademark law in your jurisdiction may provide a claim. In the United States, the Anticybersquatting Consumer Protection Act addresses bad-faith registration of a distinctive mark, and it does allow damages.

Neither route is automatic and neither is fast. A registered trademark makes both considerably stronger. For a persistent or valuable dispute, talk to qualified counsel before you send a demand or open a negotiation.

How do you find typosquatted domains?

Three methods, and they are complementary rather than alternatives.

  1. Generate and check the variations. Work through the patterns in the table above against your own domain, then check each candidate. This finds what exists. It does not tell you what is dangerous.
  2. Listen to customers and staff. A support ticket describing an order you cannot find, or a customer mentioning an address that is nearly yours, is often the first real signal. Treat it as a lead and preserve it.
  3. Monitor for change over time. The registration is not the event that harms a customer. Activation is. Useful monitoring keeps the variation, its registry data, the page content, redirects, and certificate state together, so you can see when a quiet domain starts serving something.

Manual checking scales badly. There are far more plausible misspellings than anyone will check by hand, across more extensions than anyone will remember.

How should you respond to a typosquatted domain?

Preserve the evidence first, then match the report to the behaviour you can actually document.

  1. Capture the evidence before anything else. Record the URL, the full redirect chain, dated screenshots, the registrar and host, and what the visitor is asked to do. A page can change or disappear once someone notices attention.
  2. Confirm what it is doing. Separate a parked domain from a redirect, a copied storefront, and a credential or payment page. Similarity alone does not make a page phishing.
  3. Choose the route that fits. Copyright process for your copied assets. Trademark process for misuse of your mark. Abuse or phishing report to the registrar, host, or platform for deceptive behaviour. One site can need more than one report.
  4. Tell customers when they may have been affected. A short, factual notice on your own channels beats silence.
  5. Keep watching it. Removal is not reliably permanent, and content can return on the same domain.

Expect this to take time. Of 22 confirmed threat domains the 2026 report followed, 12 were still live when it checked again.

Should you register every typo of your domain?

No. That approach cannot succeed, and the attempt spends money that monitoring would spend better.

The realistic goal is to own the domains that protect real customer routes, and to watch the rest.

PriorityWorth registering
FirstYour primary domain, plus the extensions customers in your markets expect
NextThe one or two misspellings closest to your actual name
SituationalExtensions used in paid campaigns or regional stores, or a pattern you have already seen abused

Point defensive registrations at your real store, keep them renewed, and revisit the list when the business enters a new market. Defensive registration covers the decision in more detail.

What does Recon do about typosquatting?

Recon handles the generation-and-checking work that does not scale by hand. It generates 100+ lookalike variations of your domain, checks them across 1,500+ TLDs, and keeps the evidence next to each finding — registry data, redirects, page content, certificate state, and public threat-list results.

Detection runs in real time on every plan. Alerting differs: the free plan watches 10 lookalike domains and reports in a monthly digest, so a clone found today may reach you up to four weeks later. The paid plan is $24/month or $220/year, tracks 200 domains, sweeps daily, and sends clone alerts as they happen. It includes a 14-day free trial and DMCA takedown templates.

Recon does not file takedowns for you. It finds the domain, shows you what it is serving, and gives you the evidence and templates to report it yourself. Its risk grading is a triage aid — the page and the customer route decide whether you watch, fix, notify, or report.

You can run a scan on your own domain before installing anything.

FAQ

Q: Can I stop typosquats being registered in the first place?

A: No. Domain registration is open, and no brand can reserve every variation of its name. The achievable goal is to notice registrations early, see when one becomes active, and respond with evidence.

Q: How long does removal usually take?

A: It varies by provider, jurisdiction, report type, and how well the evidence is documented. A clear-cut trademark case may resolve in days. Others run for weeks, and some domains stay live. Keep monitoring throughout.

Q: Do browsers protect customers from this?

A: Partly. Browsers warn on domains that appear in public threat lists, and they restrict some mixed-alphabet addresses. Both protections lag new registrations, and the 2026 report found live clone storefronts that no blocklist had flagged.

Q: Is a domain that resolves to nothing safe to ignore?

A: Not permanently. About 89% of registered lookalikes resolve to nothing, but a sample of those dormant domains still turned up live Shopify storefronts at 2.9%. Record it and recheck it if its content, redirect, or certificate changes.

Q: Should I contact the typosquatter directly?

A: Usually not first. An approach can raise the price of the domain or prompt the page to change before you have captured evidence. Preserve the record first, and take advice before negotiating on a dispute that matters.

Want us to monitor this for you?

Get automated brand security monitoring for your Shopify store with Recon.

Install on Shopify