Typosquatting is the practice of registering a domain name that differs from a well-known one by a probable typing error - a missing letter, a doubled letter, two characters swapped - in order to collect the visitors who make that error. It exists because typing is imperfect and the domain name system is literal. A browser pointed at a misspelling resolves whatever sits at that address, and whoever owns it receives the traffic. For more than two decades that traffic has been sold through pay-per-click advertising on parked pages, routed through affiliate links, or used for phishing and malware. Since 2016 the same trick has been applied to open-source software registries, where a misspelt package name can place malicious code on a developer's machine.

How the traffic is captured and sold

Researchers group the misspellings into a handful of generation models. A 2016 survey led by Jeffrey Spaulding listed character omission (exmple.com for example.com), permutation of adjacent characters, substitution with a neighbouring key, replacement of one character with any other, and insertion of an extra one. Soundsquatting registers homophones; research by Nick Nikiforakis and co-authors found 21.5% of soundsquat candidates generated from the Alexa top 10,000 sites already registered.

The dominant revenue model has been advertising. A registrant points the typo domain at a parking provider, which serves a page of related-search links. A visitor who clicks one reaches a results page of sponsored ads, the advertiser pays per click, and the revenue is split between the ad network, the parking company and the domain owner. Google's version, AdSense for Domains, fed those clicks into its Search Partner Network; Google's Help Center describes a parked domain as "a web address that was purchased but not thoroughly developed", and registrars and speculators used the format as passive income.

In a paper presented at the Financial Cryptography conference in 2010, Benjamin Edelman and Tyler Moore found at least 938,000 typo domains aimed at the top 3,264 .com sites. Of more than 285,000 they crawled, 80% carried pay-per-click ads and the rest redirected elsewhere. Google ads appeared on 57% of typo sites and Yahoo's on 21%, and 63% of the Google-funded domains used one of only five advertising accounts. They estimated that typos of the top 100,000 sites drew at least 68.2 million visitors a day and earned Google about $497 million a year, a back-of-the-envelope figure, since Google does not report revenue at that level.

Other models skip the ad network. A typo domain can redirect to the genuine brand through an affiliate link, so the brand pays commission on its own customers. It can host a lookalike login page. Or it can mimic a company convincingly enough to open a business relationship, which is how a 2026 attack on a Google Ads agency worked: a look-alike domain registered on April 7 redirected visitors to the real company's site while its owner sought manager-account access.

Origin and evolution

The term was in use by the late 1990s. In November 1999 John Zuccarini registered joescartons.com, joescartoons.com and three similar names that imitated a Flash cartoon site, joecartoon.com. Visitors were "mousetrapped" in a chain of ads, each click paying him between ten and twenty-five cents. When the US Court of Appeals for the Third Circuit ruled against him on June 15, 2001, it noted that "typosquatting" was Zuccarini's own term, and called his conduct "a classic example of a specific practice" the law was designed to prohibit. Damages were set at $10,000 per domain.

That law was the Anticybersquatting Consumer Protection Act (ACPA), enacted in November 1999. It makes liable anyone who, with "a bad faith intent to profit", registers, traffics in or uses a domain "identical or confusingly similar" to a distinctive mark, and lets plaintiffs elect statutory damages of $1,000 to $100,000 per domain name. A parallel, non-court route arrived the same year. The World Intellectual Property Organization (WIPO) delivered its report to the Internet Corporation for Assigned Names and Numbers (ICANN) on April 30, 1999; ICANN adopted the Uniform Domain-Name Dispute-Resolution Policy (UDRP) on August 26 and approved its text on October 24, and complaints were accepted from December 1, 1999.

Enforcement escalated. The Federal Trade Commission (FTC) sued Zuccarini in October 2001 over more than 5,500 misspelt addresses, including 15 variations of cartoonnetwork.com; a 2002 order required him to give up $1.8 million. The Truth in Domain Names Act of April 30, 2003 made it a crime to use a misleading domain name to lure people to obscene material, with heavier penalties where minors are the target, and Zuccarini pleaded guilty to 49 counts on December 10, 2003, the first case under the act. A 30-month prison sentence was announced on February 26, 2004.

Attention then turned to the money. In 2007 trademark owners filed Vulcan Golf v. Google in Illinois, challenging AdSense for Domains under the ACPA; class certification was denied on December 18, 2008, the court pointing to UDRP and individual lawsuits as better routes. That same month Verizon won $33.15 million against registrar OnlineNIC over 663 domains, $50,000 each, upheld in August 2009.

The package-registry form emerged in 2016. Nikolai Tschacher, a German student, uploaded 214 misspelt packages to PyPI, RubyGems and npm, and recorded 17,289 distinct IP addresses running his harmless notification code, at least 43.6% with administrator rights. Attackers followed: between July 19 and 31, 2017, an npm account published 39 packages including crossenv, a misspelling of cross-env, that sent environment variables to a remote server. In March 2024, according to Phylum, 566 typosquatted packages targeting libraries such as requests and TensorFlow hit PyPI, which suspended new registrations.

Why it matters for marketers

Typosquatting can make a brand pay for traffic it would have received anyway, through affiliate commissions or bids on search inventory that typo pages resell. Parked pages were for years one of the oldest surviving arbitrage surfaces in search, selling clicks from addresses whose only asset was their resemblance to someone else's.

Misspellings also reach the auction directly. Since 2014, close variants including misspellings have been compulsory for exact-match keywords in Google Ads, so a mistyped brand query can trigger an ad bid on the correct term. Google's trademark policy states that it will not restrict "trademarks as keywords", only certain uses in ad text.

Google strengthened its Misrepresentation policy against ads impersonating brands and public figures from March 2024, with immediate suspension. Its report released on April 16, 2026 recorded 421.5 million ads blocked or removed for misrepresentation in 2025, against 8.3 billion in total. The Morphixx malvertising campaign sent mobile users in the UK and Germany to a counterfeit BBC website.

Limitations and disputes

The law reaches only part of the problem. The ACPA requires a distinctive or famous mark and bad faith, so misspellings of generic words are fair game, and courts have carved out exceptions; in Lamparello v. Falwell (2005) the Fourth Circuit held that a criticism site using a mark was not cybersquatting. The UDRP is faster but offers only transfer or cancellation, no damages, so a squatter loses a domain and can register another.

Defensive registration does not scale either: permutations multiply with every new top-level domain, and the Spaulding survey found that only 156 of the Alexa top 500 sites had made defensive registrations.

The role of intermediaries remains contested. Edelman and Moore argued that ad networks financed most typosquatting, yet Vulcan Golf never produced a class-wide ruling on that question. Their revenue figure, as they acknowledged, rested on indirect data. Package registries face their own trade-off: name-similarity checks catch obvious copies but can block legitimate projects, and npm's then chief technology officer, CJ Silverio, conceded in 2017 that such attacks would probably not be caught immediately.

Typosquatting is not...

  • Cybersquatting is the umbrella term: registering a domain identical or confusingly similar to a mark in bad faith, often the exact brand name to sell back. Typosquatting is the subset that depends on user error. US law treats both under the ACPA.
  • Combosquatting pairs a correctly spelt trademark with extra words, such as a brand plus "login" or "support". A study presented at the ACM CCS conference in 2017, led by Panagiotis Kintis, analysed 468 billion DNS records over almost six years and found nearly 60% of abusive combosquatting domains active for more than 1,000 days.
  • Domain spoofing in programmatic advertising involves no registration at all. A seller declares a premium domain in a bid request while the ad runs elsewhere. The Financial Times found its inventory misrepresented on 10 display exchanges in 2017, and the countermeasure is ads.txt, launched by IAB Tech Lab on May 17, 2017.
  • Expired domain abuse means buying a lapsed domain and repurposing it to manipulate search rankings; the address is genuine, not a misspelling.

Recent developments

Google removed parked domains from the Search Partner Network on February 10, 2026, completing an opt-out begun in 2025. On January 14, 2026 WIPO reported more than 6,200 domain name cases in 2025, its highest annual caseload, after 6,168 in 2024.

In January 2026, marketers were targeted by a fake "OpenAI Advertising GPT" beta whose company name was chosen to sound official without copying OpenAI exactly. Surfshark counted 212 Grand Theft Auto 6-themed domains by August 15, 2026, about one in four with scam intent, and projected more than 750 by the game's November 19 release. Meta, which said it removed more than 134 million scam ads in 2025, has filed more than 60 lawsuits covering abuses including brand impersonation.

Timeline

  • April 30, 1999 - WIPO delivers its domain name report to ICANN
  • August 26, 1999 - ICANN adopts the UDRP; text approved October 24, 1999
  • November 1999 - Anticybersquatting Consumer Protection Act enacted in the US; Zuccarini registers Joe Cartoon misspellings
  • December 1, 1999 - First UDRP complaints accepted
  • June 15, 2001 - Third Circuit rules in Shields v. Zuccarini
  • October 2001 - FTC sues Zuccarini over more than 5,500 misspelt domains
  • April 30, 2003 - Truth in Domain Names Act enacted
  • February 26, 2004 - Zuccarini's 30-month sentence announced, the first case under the act
  • 2005 - Fourth Circuit decides Lamparello v. Falwell
  • December 2008 - Class certification denied in Vulcan Golf v. Google; Verizon wins $33.15 million against OnlineNIC
  • 2010 - Edelman and Moore estimate 938,000 typo domains targeting the top 3,264 .com sites
  • 2014 - Close variants, including misspellings, become compulsory for exact match in Google Ads
  • June 8, 2016 - Tschacher publishes results of typosquatting PyPI, RubyGems and npm
  • May 17, 2017 - IAB Tech Lab launches ads.txt
  • July 19-31, 2017 - crossenv and 38 other malicious packages live on npm
  • 2017 - Combosquatting study presented at ACM CCS
  • March 2024 - 566 typosquatted packages hit PyPI; Google begins impersonation enforcement
  • January 14, 2026 - WIPO reports a record 2025 caseload
  • February 10, 2026 - Google removes parked domains from the Search Partner Network
  • April 7, 2026 - Look-alike domain registered for an attack on a Google Ads agency
  • August 15, 2026 - Surfshark counts 212 GTA 6-themed domains

Summary

Who. Domain speculators and criminals register typo domains; parking companies, registrars and ad networks have monetised them. Brand owners, WIPO, ICANN, US courts, the FTC and package registries such as PyPI and npm police the practice.

What. Typosquatting is the registration of a domain name, or a software package name, that differs from a popular one by a likely typing error, so that mistaken visitors or installers can be monetised through ads, affiliate redirects, phishing or malware.

When. It emerged in the late 1990s, was addressed by the ACPA and UDRP in 1999, peaked commercially with parked-page advertising in the 2000s, spread to package registries from 2016, and lost Google's parked-domain ad channel on February 10, 2026.

Where. It operates in the domain name system across all top-level domains, on parked pages and lookalike sites, in search ad auctions through misspelt queries, and in open-source registries.

Why. Typing errors are predictable and domain resolution is literal, so traffic meant for a famous name can be captured for the cost of a registration. That traffic is worth money to advertisers and to attackers, which is why it has been sold, litigated and defended for more than 25 years.