Free Typosquat & Homoglyph Checker

Enter your domain. We generate the typo and look-alike variants a squatter would reach for and check which are already registered.

Variant techniques
Five

Generating & checking variants...

What is a Typosquat Checker?

A typosquat checker generates the domains that look or read like yours, the ones a visitor could land on by mistyping, and the ones an attacker registers on purpose to impersonate you, and tells you which are already registered.

It works through the same five techniques squatters use: dropping a letter, doubling one, swapping two, hitting the neighbouring key, and substituting a look-alike character (an o for a 0). Each variant is checked as a name against the authoritative registry, so a "registered" result is a live look-alike, not a guess.

How to find look-alikes of your domain
  1. Enter the domain you want to protect, your exact brand name and extension.
  2. We generate look-alike variants across five techniques and check each against the registry in real time.
  3. Registered look-alikes are listed first, those are the live risks. Inspect who holds one, and monitor the set so you hear when a new one appears.

Why Watch Your Look-Alikes

  • Registered is the finding: an available look-alike is a gap you can close; a registered one is already out there, and it is where phishing and brand impersonation start.
  • Checked as names, privately: we ask the registry whether each variant exists, we never fetch the look-alike sites, and we never log or sell the names we generate.
  • One pass, not fifty: hand-checking every typo of a brand is a chore no one does. This is the whole set in one look, sorted so the live ones are on top.

The Five Typosquatting Techniques

Squatters do not invent names at random, they run a handful of mechanical transforms on yours. These are the five this tool covers.

Technique Example on "example" What it exploits
Missing letter exmple, exaple A single dropped character. The commonest genuine typo, and the easiest for a visitor to make without noticing.
Doubled letter exaample, examplle A character typed twice. Slips past the eye because the shape of the word is almost unchanged.
Swapped letters exapmle, examlpe Two adjacent characters in the wrong order, a fast-typing error, and one people rarely re-read closely enough to catch.
Neighbouring key wxample, exsmple A letter replaced by the one beside it on a QWERTY keyboard. The classic fat-finger slip on mobile especially.
Look-alike character exampl3, exampie A character swapped for one that looks like it, o/0, l/1, i/1, s/5. Not a typo at all; a deliberate impersonation that reads correctly at a glance.

How to Read the Result

The list is sorted so the ones that matter are first. Here is what each state is telling you.

Registered look-alikes

Amber, the finding

Someone holds this variant. That is where a phishing page or a spoofed email domain lives, so these are listed first. It is not proof of bad intent, but it is worth knowing who holds it and what it points at.

Look up the holder

Available look-alikes

Grey, the gap

This variant is unregistered. Whether to defensively register the closest few is a judgement call: the obvious homoglyphs and the one-letter typos are cheap insurance; the long tail is not worth chasing.

How each was generated

The label

Each variant carries the technique that produced it, a missing letter, a look-alike character, and so on, so you can see at a glance which kinds of confusion your name is most exposed to.

"Not checked" is not "clear"

The honest gap

We check variants under a time budget so the page stays fast. Anything past the budget is shown as not-checked rather than assumed clear. Run any of them by name for a definitive answer.

What Typosquatting Actually Is

Typosquatting, also called URL hijacking, is registering a domain that is a near-miss of a real one, to catch the traffic and trust that belongs to the original. It is one of the oldest tactics on the web because it is cheap to do and works on inattention rather than on breaking anything.

A squatted look-alike is used to:

  • Phish: a login page that looks like yours, on a domain that reads like yours.
  • Spoof email: a look-alike domain that passes a casual glance in the "from" line.
  • Skim traffic: ads or affiliate redirects on the mistype of a popular name.

Why It Pays, and Why It Persists

The economics are brutally simple: a domain costs a few dollars, and a single deceived customer, redirected click, or captured credential can more than cover it. A squatter registering variants of a hundred brands only needs a fraction to convert.

That is also why it never stops. As your brand grows, new variants become worth registering, so a name that is clean today accrues look-alikes over time. Checking once tells you where you stand now; monitoring is what tells you when it changes, and the brand-protection playbook is how you respond.

What This Checker Does and Does Not Cover

It covers the mechanical look-alikes of your exact name in its own extension. A few things are deliberately out of scope, so you know where to look further:

  • Same name, other extensions, a squat on your-name.net or .co is a different search. Run your exact name through the availability checker to sweep extensions, and watch the ones that matter.
  • Combosquatting, additions like your-name-login.com or secure-your-name.com are not near-misses of the label, so they are not generated here. They need a keyword search, which continuous brand monitoring covers.
  • Internationalised (IDN) homoglyphs, Unicode look-alikes that resolve to punycode are a distinct class from the ASCII confusables here. They matter, but they are a separate tool, not a variant of this one.
  • Registered is not automatically malicious, a look-alike may be held by you, a partner, or a passive investor. The tool surfaces the exposure; judging intent is the next step, starting with who holds it.

Why Look-Alike Exposure Matters

01

Phishing starts here

A convincing phishing page needs a convincing address. A registered look-alike of your domain is the foundation of one, aimed at your customers and using your trust.

02

Email spoofing

A look-alike domain that passes a glance in the "from" line is how business-email-compromise fraud gets its foot in the door, an invoice from a domain one character off from yours.

03

Leaked traffic

Every visitor who mistypes your name and lands on a squatter's parking page or a competitor's redirect is a customer you paid to acquire and then lost at the door.

04

Borrowed trust

Whatever a look-alike does, scam, malware, or just low-quality ads, it does it wearing a name that reads as yours, and the reputational cost lands on you, not on the squatter.

Who Checks for Typosquats

The same look-alike sweep serves a different job depending on who is asking.

Brand Owners

See the look-alikes of your name that are already out there, and decide which to register defensively and which to watch.

For brand protection

Security & IT Teams

Map the phishing and email-spoofing surface around your primary domains, and feed the registered ones into your monitoring.

For IT & MSPs

Legal & Trademark

Surface infringing registrations for a UDRP filing or a cease-and-desist, with the exact variants and who holds them.

For legal & trademark

Agencies

Run a look-alike audit as part of a brand-health check, and set up ongoing monitoring for the client.

For agencies

Once You Have Found One

A registered look-alike is the start of a response, not the end of one. Here is where it goes.

01

Monitor the whole set

Look-alikes appear over time. Put your name and its variants under monitoring so a new registration reaches you as an alert, not as a surprise.

Set up monitoring
02

Find out who holds it

A WHOIS lookup on a registered look-alike shows the registrar, the dates, and the status codes, the first evidence for a defensive action.

Run a WHOIS lookup
03

Watch an available one

For a variant that is unregistered but worth having, a free watch tells you the moment it is registered by someone else, so you can act before it is used.

Start a free watch
04

Read the playbook

The brand-protection guide walks through defensive registration, monitoring, and the takedown routes for a look-alike that is actually being used against you.

Brand protection

Frequently Asked Questions

Common questions about typosquatting, look-alike domains, and defending a brand.

What is typosquatting?

Typosquatting, also called URL hijacking, is registering a domain that is a near-miss of a real one, a dropped letter, a doubled letter, a look-alike character, to catch traffic and trust that belongs to the original. It is used for phishing, email spoofing, and skimming mistyped traffic.

What is a homoglyph attack?

A homoglyph attack swaps a character for one that looks like it, a zero for the letter o, a one for a lowercase L. Unlike a typo, it is deliberate: the domain reads correctly at a glance, which is exactly what makes it effective for impersonation. This tool covers the common ASCII confusables.

How does the checker decide if a variant is registered?

It queries the authoritative registry (via RDAP and WHOIS) for each variant, as a name, it never fetches the look-alike website. A "registered" result means the registry has a record of that name right now; an "available" result means it does not.

Does a registered look-alike mean I am being attacked?

Not necessarily. A variant may be held by you, a partner, a passive investor, or an unrelated business. The tool surfaces the exposure; judging intent is the next step, and it starts with a WHOIS lookup to see who holds the name and what it points at.

Should I register all the available look-alikes?

No, the long tail is not worth chasing. The sensible defensive set is the obvious homoglyphs and the one-letter typos of your primary name; those are cheap insurance. Beyond that, monitoring for new registrations is a better use of budget than owning every possible variation.

Why are some variants marked "not checked"?

To keep the page fast, variants are checked under a time budget. Anything past the budget is shown as not-checked rather than assumed clear. You can confirm any of them by running the exact name through the availability checker.

Which techniques does the tool cover?

Five: a missing letter (omission), a doubled letter (repetition), two swapped letters (transposition), a neighbouring-key slip (adjacent key), and a look-alike character (homoglyph). Together these account for the overwhelming majority of live typosquats.

Does it check other extensions, like .net or .co?

No, this tool checks look-alikes of your exact name in its own extension. A squat on the same name in a different extension is a different search; run your exact name through the availability checker to sweep extensions.

What about combosquatting, like brand-login.com?

Additions like brand-login.com or secure-brand.com are not near-misses of the label itself, so they are out of scope here. They need a keyword-based search, which continuous brand monitoring covers.

What can I do about a malicious look-alike?

Options range from a cease-and-desist to a UDRP or URS filing with the registrar, and a report to the hosting provider or browser safe-browsing lists if it is actively phishing. Start by documenting the registration with a WHOIS lookup; the brand-protection guide covers the routes in detail.

Is my search private?

Yes. We do not log, store, or sell the domain you enter or the variants we generate, and we check names against the registry rather than visiting the look-alike sites.

How often should I check?

A one-off check tells you where you stand today, but look-alikes accrue as a brand grows. For anything you are actively defending, continuous monitoring is the right tool, it tells you when a new variant is registered rather than relying on you to re-run the check.

Start Today

Start Monitoring & Catching Domains Today

Join founders, agencies, and domainers already protecting their portfolio. Your first 5 domains are free.

Create Free Account

No credit card required • Cancel anytime