typosquatting checker.
Generate the typos, homoglyphs, and TLD swaps that could impersonate a client domain. See which are registered and which are configured for email before the client sees the phish.
The domains attackers register to be mistaken for you.
Typosquatting is registering a domain that looks almost like yours to catch mistyped URLs and impersonate you in email. We enumerate the common variations, then resolve each one against DNS.
keyboard typos
Missing, repeated, and swapped characters, plus fat-finger substitutions and insertions based on which keys sit next to each other on a QWERTY keyboard.
look-alike characters
Homoglyphs that read as one another in common fonts: rn for m, vv for w, cl for d, and digit-for-letter swaps like 0 for o and 1 for l.
vowel and hyphen tricks
Swapped vowels (paypel for paypal) and added or removed hyphens, both cheap ways to land a domain that still reads correctly at a glance.
TLD swaps
Your exact name on a different extension — .net, .co, .io, .org and more — which is one of the most common and convincing impersonation tricks.
added words
Names padded with words like login, secure, account, and support, the phrasing phishing pages use to look official.
live registration & mail
Every candidate is resolved against DNS. Registered domains are flagged, and MX records surface the ones configured to receive email — a strong abuse signal.
A registered look-alike is a loaded weapon.
email impersonation
A look-alike configured for mail can support convincing impersonation. To a hurried employee or customer, invoice@paypel.com looks close enough to trust.
phishing & credential theft
Attackers clone your login page on a near-identical domain. Victims who mistype your URL, or click a lookalike link, hand over passwords without noticing the swap.
traffic and brand theft
Even parked, a typo domain siphons visitors to ads or competitors and erodes trust in your brand every time someone lands somewhere they didn't expect.
it happens quietly
Registrations are cheap and silent. The first time most teams learn a look-alike exists is when a customer forwards a phishing email that used it.
Typosquatting questions, answered.
Typosquatting (also called URL hijacking or brandjacking) is registering a domain that closely resembles a legitimate one, relying on typos, look-alike characters, or a different extension. The goal is to catch people who mistype a URL or don't look closely, then use the domain for phishing, malware, ad revenue, or email impersonation.
We take the registrable part of your domain and apply the same permutation techniques attackers and tools like dnstwist use: character omission, repetition and transposition, keyboard-adjacent substitutions and insertions, homoglyphs, vowel swaps, hyphenation, TLD swaps, and common phishing affixes. Each generated candidate is then resolved against DNS to see if it's registered.
A candidate is reported as registered when it has an A record (an IP address) or NS records (delegated name servers). That's a strong signal the domain exists and is controlled by someone. A domain with no A and no NS records is almost certainly unregistered or unused.
MX records mean the domain is configured to receive email, a common signal that it is being prepared for email use. They do not prove active sending, but a registered, mail-capable look-alike is higher risk for phishing and business email compromise, so we surface it separately.
First confirm whether it's yours — many companies defensively register common typos and point them at their real site. If it isn't yours, check where it resolves and whether it has mail set up. Genuine impersonation domains can be reported to the registrar and, for trademark abuse, through ICANN's UDRP process. Defensively registering the most convincing variants is often the cheapest protection.
No tool can. We generate a capped set of the most common ASCII permutations, so extremely long names and exotic tricks like internationalized (Unicode) homoglyph domains aren't all covered yet. Treat the results as the high-probability shortlist an opportunistic attacker would reach for first, not an exhaustive audit.
Look-alikes are one part of the client domain.
The free scan checks look-alikes, email auth & DMARC, SSL & domain expiry, and blacklists together from public records. One result, no signup.
Keep checking the same failure point.
Use the related tools one at a time, or run all four posture checks together.