Domain name watching: detect typosquatting before it becomes phishing

Domain name monitoring for typosquatting means watching new registrations for names that copy or imitate your marks, such as misspellings, added words or a different extension, so you can act before they carry a phishing site or fake email. It matters because most phishing domains are registered on purpose: Interisle Consulting Group found that 74% of the domains reported for phishing between May 2025 and April 2026 were registered by attackers, not hacked. This guide is for brand, security and legal teams deciding how to set up a watch.

Key takeaways

  • About three in four phishing domains are attacker-registered, so a registration watch can spot many of them before they are used.
  • Typosquatting covers misspellings, swapped or look-alike characters, added terms such as “login” or “support”, hyphens and other extensions.
  • The Trademark Clearinghouse (TMCH) sends free ongoing notifications for exact matches and variations of recorded marks in new gTLDs and in .com, .net and .org.
  • TMCH notices are a starting point, not a full watch: they depend on recorded labels and do not assess risk or cover every ccTLD.
  • Every hit needs triage: preserve evidence, check use, report abuse, and choose between the URS, the UDRP, a ccTLD procedure or court.

What is typosquatting and why does it lead to phishing?

Typosquatting is registering a domain that differs slightly from a brand so that users mistype it, misread it or trust it. Common patterns include:

  • Omissions, additions or transposed letters (examplle, exmaple).
  • Look-alike characters, including internationalised domain names (IDNs) that swap a Latin letter for a Cyrillic or Greek one.
  • The brand plus a term that invites a click: login, secure, account, support, pay, or local words such as “cliente” or “pagamento”.
  • Hyphenated versions and the same name in another extension: a new gTLD, a ccTLD or a variant such as .co for .com.

Interisle’s Phishing Landscape 2026 explains why this matters. Its summary findings of 24 June 2026 compare May 2024 to April 2025 with May 2025 to April 2026:

Measure 2024-25 2025-26 Change
Phishing attacks 1,963,390 4,251,720 +117%
Unique domains reported for phishing 1,542,922 3,103,438 +101%
Maliciously registered phishing domains 1,192,794 2,295,824 +92%
Attacks using a subdomain provider 256,026 432,990 +114%

In a later post of 10 July 2026, Interisle puts the average across all top-level domains at 74% maliciously registered and 26% compromised, and notes that about three quarters of phishing domains have been registered maliciously in recent years. On 30 June 2026 it also reported that new gTLDs have had the worst ratio of phishing domains to registrations in every study period since 2021. A domain registered by an attacker exists before the attack starts, and that gap is where monitoring pays off.

How does domain name monitoring for typosquatting work?

A watch combines several data sources, each with limits:

Source What it detects Coverage Limits
TMCH Claims and Ongoing Notifications Registrations matching your recorded labels and their variations New gTLDs and, per the TMCH, popular legacy TLDs such as .com, .net and .org Requires a TMCH record; you must activate the service
gTLD zone files through ICANN’s CZDS Newly delegated domain names, compared daily against your watchlist Participating gTLD registries Approved requesters only; no ccTLDs
ccTLD sources New names in country-code extensions Varies by registry Many ccTLDs do not publish zone files
Use signals Mail (MX) records, live content, look-alike login pages Any domain already flagged Needs regular checks and analyst review

The Centralized Zone Data Service (CZDS) gives approved requesters, such as IP practitioners and researchers, access to gTLD zone files. Professional watch services combine this with ccTLD data and similarity algorithms, then filter the noise so a lawyer reviews only the hits that matter.

TMCH notifications or a full domain watching service?

Under the TMCH requirements for the 2026 base registry agreement (12 March 2026, section 3.2.1), every new gTLD must run a Claims period for at least the first 90 days of general registration: anyone trying to register a name matching a recorded mark sees a warning, and the mark holder is told if they go ahead. After that, the TMCH Ongoing Notifications service keeps sending alerts for as long as the record is active, at no extra cost for exact matches and for variations such as “containing” or accented forms.

That is useful, but it is not a full watch. It covers the labels you recorded, not every typo pattern; it does not tell you whether a name is parked, sending email or hosting a fake login page; and country-code extensions such as .es, .mx or .br are outside the ICANN framework. With the 2026 gTLD round adding new extensions, our recommendation is to keep TMCH as the base and add a watch that covers ccTLDs, typo variants and use.

What to do when the watch finds a suspicious domain

  1. Preserve evidence: screenshots, registration data, MX and DNS records, with dates.
  2. Classify the risk: parked page, pay-per-click links, active email, or a live phishing page.
  3. For live phishing, report abuse to the registrar and the hosting provider at once; that is often the fastest takedown.
  4. For clear-cut cases in new gTLDs, consider the Uniform Rapid Suspension (URS): a faster, lower-cost procedure that suspends the name for the rest of its registration period, on clear and convincing evidence.
  5. To take control of the name, use the UDRP for gTLDs or the relevant ccTLD procedure; the WIPO Center reported over 6,200 domain name cases in 2025, including cases that halted phishing campaigns.
  6. Escalate to civil or criminal action when there is fraud or repeat conduct.

What this means for your business

  • Build the watchlist from your marks, key product names and the words your customers search with, in the languages of your markets: Spanish, Portuguese, French and English across the corridor.
  • Record core marks in the TMCH and activate Ongoing Notifications.
  • Agree an escalation path between legal, security and marketing, with response times.
  • Review the watch quarterly: new products, new markets and new gTLDs change what needs to be on it.

If you want this run as one service, our domain name monitoring and typosquatting response team can set up the watch, review the hits and take action through the right procedure in each extension.

Where domain watching programmes fail

  • Watching only exact matches. Attackers rarely register the exact brand; they add a word or change a letter.
  • Ignoring ccTLDs. A watch limited to gTLDs misses .es, .mx, .br or .co names targeting local customers.
  • Alerts without owners. A notification nobody reviews for two weeks protects nobody.
  • Jumping straight to a UDRP. When a phishing page is live, an abuse report usually comes first; the dispute procedure secures the name afterwards.
  • Weak trademark coverage. Recovery procedures rely on your rights, so check your trademark registrations across Europe, Latin America and Africa before you need them.

Frequently asked questions

What is the difference between typosquatting and cybersquatting?

Cybersquatting is the broad practice of registering a domain that targets someone else’s mark in bad faith, often to sell it or divert traffic. Typosquatting is one form of it, based on small spelling or visual differences that users miss. Both can be challenged through the UDRP or a ccTLD procedure, and both are used for phishing.

Is the TMCH Ongoing Notifications service enough to monitor my brand?

It is a good base. It is free for exact matches and variations of recorded marks and covers new gTLDs and, according to the TMCH, popular legacy TLDs such as .com. It does not cover most country-code extensions, every typo pattern or how a domain is used, so most brands pair it with a broader watch.

How quickly can a typosquatting domain be taken down?

It depends on the route. An abuse report to the registrar or host can act quickly on a live phishing page. The URS suspends clear-cut new gTLD cases faster than a UDRP, while the UDRP transfers the name, with WIPO now offering an expedited one-month track. Country-code domains follow their own procedures.

Can IP Global Guard run a domain watch for my company?

Yes. We define the watchlist with you, combine TMCH notifications with gTLD and ccTLD monitoring, review the hits and recommend action. We then handle abuse reports and dispute procedures across Europe, Latin America and Africa, coordinating local correspondents where a country-code procedure requires it, from a single point of contact.

How IP Global Guard helps you act before the phishing starts

A domain watch earns its cost when a suspicious registration reaches someone who can judge it and act the same week. IP Global Guard, the IP services line of META Channel Corporation Limited, combines domain monitoring, recovery and trademark protection with one strategy and one billing relationship across more than 25 jurisdictions; see our coverage in Europe, Latin America and Africa.

Tell us which marks, product names and markets you want watched. We will propose a watchlist, set up the monitoring and agree with your team how each type of hit is handled. Contact us to set up your domain watch.

This article is general information, not legal advice, and does not replace an assessment of your specific situation.

Sources