Typosquatting
Lookalike domain · URL hijacking
Typosquatting is registering domain names that closely mirror a legitimate one, through misspellings, swapped characters, extra words, or altered endings, to catch people who mistype an address or overlook the difference in a link. The counterfeit site usually imitates the real one to harvest logins and payments or to spread malware. It often serves as the backbone of phishing campaigns.
How we check this: Written and reviewed by the Hunch team; recognition signs reflect how the FTC/FBI describe this scam. · Last reviewed: 2026-08
Check a suspicious message now
Example
Instead of your bank's real address, a link points to a domain with one letter changed or an added word like '-secure.' The page looks identical to the genuine site, so anyone who doesn't scrutinize the address enters their credentials into the scammer's copy.
How to recognize it
- A domain with a subtle misspelling, extra hyphen, or added word
- An unusual ending (for example a different top-level domain than usual)
- A link whose visible text differs from where it actually leads
- A familiar-looking site reached from an unsolicited message rather than your own bookmark
How Hunch flags it
Hunch keys on the lookalike-domain signal category, addresses that closely imitate a known brand, and on mismatches between a link's displayed text and its real destination, especially when paired with a credential or payment ask.
FAQ
What is typosquatting?
Registering web addresses that look almost identical to a real one to catch people who mistype it or don't notice the difference in a link.
How can I avoid landing on a lookalike domain?
Type important addresses yourself or use saved bookmarks, and read the full domain carefully before entering any login or payment details.
Is a padlock icon proof a site is real?
No. The padlock only means the connection is encrypted; scammers can obtain it too, so a lookalike domain with a padlock is still dangerous.