Typosquatting

Typosquatting is registering domain names that closely mirror a legitimate one, through misspellings, swapped characters, extra words, or altered endings, to catch people who mistype an address or overlook the difference in a link. The counterfeit site usually imitates the real one to harvest logins and payments or to spread malware. It often serves as the backbone of phishing campaigns.

Lookalike domain · URL hijacking

Check a suspicious message now

The check runs in your browser. What you paste stays on your device. It is not sent to our servers or anyone else, and nothing is stored.

The image is read on your device. It is never sent or stored.

Please don't paste other people's personal data.

Or try a real one:

Get it free

Or check it on Telegram

Example

Instead of your bank's real address, a link points to a domain with one letter changed or an added word like '-secure.' The page looks identical to the genuine site, so anyone who doesn't scrutinize the address enters their credentials into the scammer's copy.

How to recognize it

  • A domain with a subtle misspelling, extra hyphen, or added word
  • An unusual ending (for example a different top-level domain than usual)
  • A link whose visible text differs from where it actually leads
  • A familiar-looking site reached from an unsolicited message rather than your own bookmark

How Hunch flags it

Hunch keys on the lookalike-domain signal category, addresses that closely imitate a known brand, and on mismatches between a link's displayed text and its real destination, especially when paired with a credential or payment ask.

FAQ

What is typosquatting?

Registering web addresses that look almost identical to a real one to catch people who mistype it or don't notice the difference in a link.

How can I avoid landing on a lookalike domain?

Type important addresses yourself or use saved bookmarks, and read the full domain carefully before entering any login or payment details.

Is a padlock icon proof a site is real?

No. The padlock only means the connection is encrypted; scammers can obtain it too, so a lookalike domain with a padlock is still dangerous.

Related