1001Ferramentas
🎣 Security

Typosquatting Domain Generator

Generates look-alike domains by swap, omission, keyboard slip, homoglyph, bitsquatting and other TLDs to monitor typosquatting.

Use this with a domain your organization owns. The list is a monitoring target: feed it to your DNS or certificate transparency watch, open abuse reports for the ones already impersonating you, and defensively register the handful closest to your brand. Generating a list is not a suggestion to register someone else's name.

Protocol, www, port and path are dropped. Two-part suffixes such as com.br are kept whole, so the permutations hit the registrable name only.

Strategies

What the list is and is not

Every name here is a permutation, not a finding. The page never queries DNS, WHOIS or certificate logs, so it cannot tell you whether a variant is registered, parked or already serving a fake login. Checking registration is the next step, and it belongs to a resolver or a WHOIS/RDAP lookup you run against the list.

Bitsquatting is the strategy people usually skip: it flips a single bit of one character, which is what a stray memory or transmission error does to a request, and lands on names nobody would type on purpose. Homoglyphs cover the visual tricks that survive a quick glance in a mail client, such as rn standing in for m. Priority for defensive registration usually goes to the variants of the first three groups, since those are the ones a human actually mistypes.

Map the domains that look like your brand

Registering a domain that resembles yours takes no creativity: swap two letters, drop a character, hit the neighbouring key or hang the same name on another extension. The generator walks those ten strategies over the registrable name of your domain, groups the output by strategy and hands you a list ready to copy or download as a txt file.

The name is split from the suffix before any permutation, and two-part suffixes such as com.br are kept whole, so the swaps never touch the extension by accident. One domain can come out of two strategies; when that happens it stays with the first one in order, and the count at the top keeps matching the sum of the groups. A subdomain you type is reported and left out.

Bitsquatting is the strategy manual lists tend to miss: it flips a single bit of one character, which is what a stray memory or transmission error does to a lookup, and reaches names nobody would type on purpose. Homoglyphs cover the visual trick that survives a quick glance in a mail client, such as the pair rn standing in for the letter m and a zero replacing the letter o.

Frequently asked questions

Does the tool say whether a variant is registered?
No, and that is deliberate: the page makes no DNS, WHOIS or certificate log query. What comes out of here is the set of possible permutations. Checking registration is the next step, with an RDAP lookup or a bulk resolution run against the list you download.
Why did the subdomain I typed disappear?
Because typosquatting happens on the registrable name, the part someone buys from a registrar. An attacker does not register shop.yourbrand.com: they register a variant of yourbrand and build whatever subdomain they like afterwards. The page tells you what it ignored and shows the real target of the permutations.
Should I register every variant on the list?
You could not, and it would not help. Common practice is to defensively register a handful, the ones matching typos a human actually makes, and put the rest under DNS and certificate transparency monitoring. When a variant shows up serving content that imitates your brand, the route is an abuse report to the registrar and the hosting provider.

Related Tools