Logo
Logo

PRODUCTS

TOOLS

pricing background

Free Domain Typosquatting Checker

The typosquatting checker generates every common typo, lookalike, and homoglyph variant of your domain, then checks each against WhoisFreaks' database of 906M+ registered domains. Every match returns WHOIS contact records and DNS records, so security and brand teams can move directly to takedown or monitoring.
1528+
TLDs
693M+
Active Domains
906M+
Domains Tracked
3872M+
WHOIS Records
5290M+
Host Names
16B+
DNS Records

Enter your domain to scan for typo and lookalike variants

Try these examples:

What is Typosquatting?

Typosquatting is the practice of registering domain names that are misspellings, keyboard slips, or visual lookalikes of legitimate brand domains - then using those domains for phishing, malware delivery, ad fraud, or brand impersonation. A typosquatting domain catches users who mistype a URL in the browser (typing youtub.com instead of youtube.com) or who click a malicious link styled to look like the real one (g00gle.com using zeros instead of letter o). Common typosquatting patterns include character omissions, keyboard-adjacent slips, vowel swaps, hyphenated variants, TLD swaps (.co instead of .com), ASCII homoglyphs (rn looking like m), and Internationalized Domain Name (IDN) Punycode homoglyphs using Cyrillic or Greek lookalike characters. The Anticybersquatting Consumer Protection Act in the United States makes typosquatting on registered trademarks actionable with statutory damages from $1,000 to $100,000 per domain.

Character & Keyboard Typos
Homoglyph Lookalikes
TLD Swaps
IDN Punycode Variants

Feature: Typosquatting Checker generates every common typo, homoglyph, and lookalike variant of your domain in one pass

Feature: Each variant is checked against WhoisFreaks' database of 906M+ registered domains across 1528+ TLDs

Feature: Every match returns full WHOIS records (registrant, registrar, registration date) and DNS records (A, MX, NS)

Feature: Free web tool covers individual scans; bulk scanning and scheduled monitoring available through the API

For continuous brand-keyword monitoring with daily re-scans, automated alerting on new typosquatting registrations, and integration into SOC and brand-protection workflows, the WHOIS Database with newly-registered-domain coverage provides programmatic access to the full domain index with date-range filtering and webhook notifications.

Who uses the typosquatting checker?

Typosquatting checks show up in four very different workflows: brand protection teams hunting cybersquatters before they're weaponized, SOC teams catching phishing infrastructure during the registration phase, M&A teams running pre-announcement defensive scans, and IT teams building defensive registration lists. The four use cases below are where the typosquatting checker matters most.

Brand Protection Teams

Brand protection teams run the typosquatting checker on every trademarked term, product name, and executive name. The full typo permutation set, scanned against 906M+ registered domains, surfaces lookalike registrations that feed directly into UDRP filings and registrar takedown requests. Pair with the WHOIS Lookup to pull registrant details for every match.

Security Operations Teams

Phishing campaigns typically register lookalike domains days or weeks before launching attacks. SOC teams run the typosquatting checker on their organization's domain and top product names on a recurring schedule, so newly registered typo variants surface before any phishing email is sent. The WHOIS Database API integrates into SIEM and SOAR pipelines for scheduled bulk scans across all brand-keyword permutations.

M&A and Corporate Development Teams

Before announcing an acquisition or new product, corporate development teams run the typosquatting checker on the target brand, the post-deal name, and any internal codenames. Pre-announcement scans reveal whether speculators or threat actors have already registered defensive variants, and which TLDs need defensive registration before public disclosure.

Domain Administrators and IT

Domain administrators use the typosquatting checker to build a defensive registration list. The full permutation set tells the team which typo variants are still available to register defensively (verify with the Domain Availability tool) and which are already taken, with WHOIS records on every taken domain so the team can choose between buyback, takedown, or monitoring.

Why use the WhoisFreaks Typosquatting Checker?

WhoisFreaks scans every generated typo permutation against 906M+ registered domains across 1,528+ TLDs - the full registered set, not a small TLD subset. Where most free typosquatting tools return only "registered" or "available," WhoisFreaks returns full WHOIS records and DNS data on every match, so the next remediation step is obvious.

  • Full typo permutation set generated automatically: character omissions, keyboard slips, vowel swaps, homoglyphs, TLD swaps, IDN Punycode variants, and hyphenated brand-plus-keyword patterns
  • Each registered match returns WHOIS data (registrant, registrar, registration date) and DNS records (A, MX, NS) - enough context to file UDRP, send registrar takedown requests, or feed into a watchlist
  • 24-48 hour database refresh cycle - daily or weekly scans catch new typo registrations the same week they go live; API access available through the WHOIS Database
Tip

Phishing actors favor predictable patterns: brand plus a service word (yourbrand-login, yourbrandpay), hyphenated variants, and homoglyph swaps. Run the checker against your base domain, then against your top product names and executive names. Re-run weekly, since most typo domains are registered shortly before they are used in an attack. For each match found, run a WHOIS Lookup to surface the registrant and registration date - that's usually enough evidence for a UDRP filing or registrar takedown request.

Powered by Domain Typosquats API

Domain Typosquatting FAQs

Common questions about keyword search, database coverage, and brand monitoring use cases.

What is typosquatting?

How is typosquatting different from cybersquatting?

Is typosquatting illegal?

What types of typo variations does the checker generate?

How fresh is the domain database the checker scans against?

What can I do when I find a registered typosquatting domain?