Cybersecurity

What is Cybersquatting and How Does TLD Enumeration Help?

Cybersquatting is registering a domain that trades on someone else's brand. Learn the squatting types, how TLD enumeration surfaces lookalikes, and the UDRP process to take them down.

By Inventive HQ Team

Cybersquatting is registering, trafficking in, or using an internet domain in bad faith to profit from a trademark that belongs to someone else. It ranges from grabbing the .net version of a brand that only owns the .com, to typo domains like paypa1.com, to "combosquats" like microsoft-support.net that keep the brand intact and add a trustworthy-sounding word. In the United States it is actionable under the Anticybersquatting Consumer Protection Act (ACPA); worldwide it is resolved through ICANN's Uniform Domain-Name Dispute-Resolution Policy (UDRP), which can force a transfer or cancellation in roughly two months without a lawsuit.

That is the definition an AI Overview will hand you. What it can't show you is the mechanics: the four squatting patterns attackers actually use, how a single brand string explodes into hundreds of registerable lookalikes, and the concrete detection-and-takedown workflow that turns "someone might be squatting us" into a repeatable check. The diagram, tables, and enumeration walkthrough below are built for that.

The anatomy of a squatting attack

Every squatting campaign follows the same arc: pick a brand, mint a lookalike domain, dress it up with a valid TLS certificate so browsers show the padlock, then harvest traffic or credentials. The enumeration defense runs the same string generation the attacker does — but you get there first.

How a cybersquatting attack unfolds and where enumeration intercepts it A brand string branches into lookalike domains, an attacker registers one and adds a TLS certificate to phish users; TLD enumeration and Certificate Transparency monitoring intercept the lookalike before users are harmed.

yourbrand brand string

yourbrand.co TLD swap

yourbrnad.com typosquat

yourbrand-login.com combosquat

уourbrand.com homograph (IDN)

Attacker registers + adds TLS cert

Your defense TLD enumeration lists every variant CT-log monitor flags the new cert → UDRP / ACPA takedown

Advertisement

The four squatting patterns

Not all lookalikes are equal. The pattern determines both how likely a victim is to fall for it and which takedown lever works best.

PatternExample (brand = acme.com)How it fools peopleBest defense
TLD swapacme.net, acme.co, acme.ioUser assumes the brand owns every extensionDefensively register the top 3-4; enumerate the rest
Typosquattingacme.co typo acmee.com, acme.cmKeyboard slips and dropped/doubled lettersRegister the 2-3 most-likely typos; monitor others
Combosquattingacme-support.com, login-acme.netBrand is spelled correctly; added word reads as officialCT-log + newly-registered-domain monitoring
Homograph / IDNаcme.com (Cyrillic а → xn--cme-8cd.com)Address bar looks pixel-identicalPunycode-aware browser + CT-log monitoring

The "which should I use when" rule: defensive registration is cost-effective only for the handful of exact-match and obvious-typo domains real customers type. For everything else — combosquats and homographs, which are effectively infinite — you cannot out-buy the attacker, so you detect and take down instead. Enumeration plus Certificate Transparency monitoring is that detection layer.

How TLD enumeration works

There are over 1,500 top-level domains in the ICANN root zone, from legacy generics (.com, .net, .org) to newer ones (.app, .dev, .xyz) and country codes (.co.uk, .de, .io). TLD enumeration takes your brand string and mechanically produces the registerable variant for each, then checks its live status:

  1. Generate every brand.<tld> combination from the root-zone list.
  2. Resolve each via DNS — does it have an A/AAAA record, or is it unregistered?
  3. Classify the responders: your own domains, parked/for-sale pages, active third-party sites.
  4. Prioritize anything that resolves to a live site with a valid TLS certificate — that combination is the strongest signal of an active campaign rather than a passive squatter.

Our TLD Enumerator runs this for any brand string in your browser and returns the full grid so you can spot registered lookalikes without manually querying WHOIS a thousand times.

Detection signals, ranked

Not every registered lookalike is a live threat. Triage by signal strength before you spend legal budget.

SignalWhat it meansUrgency
Live site + valid TLS cert on a lookalikeActive phishing/impersonation infrastructureHigh — act now
New TLS cert in CT logs for your brand keywordSomeone just stood up a lookalikeHigh — investigate
WHOIS privacy registration timed to a launchDeliberate, likely bad-faith registrationMedium
Parked/for-sale page on an exact-match TLDClassic squatter waiting for a buyoutMedium
Unregistered but obvious variantFuture risk, not currentLow — consider pre-registering

Takedown: UDRP vs. ACPA lawsuit

Once you confirm bad-faith use, two paths exist and they solve different problems.

UDRP (ICANN)ACPA lawsuit (US)
ForumWIPO or other approved providerUS federal court
Timeline~2 monthsMonths to years
CostFiling fees (low thousands)Litigation costs
RemedyTransfer or cancel the domainTransfer plus up to $100,000 statutory damages per domain
Use whenYou just want the domain gone, fastYou want damages or the registrant is US-based and egregious

For a UDRP complaint you must prove all three elements: the domain is identical or confusingly similar to your mark, the registrant has no legitimate interest, and it was registered and used in bad faith. Missing any one element loses the case.

A practical monitoring routine

You don't need an enterprise brand-protection suite to cover the basics:

  • Weekly: run TLD enumeration on your brand and any product names; flag new live resolvers.
  • Continuously: subscribe to Certificate Transparency log feeds filtered on your brand keyword — every new HTTPS lookalike surfaces here within minutes of issuance.
  • At launch time: watch newly-registered-domain feeds around product announcements, when combosquatting spikes.
  • Register defensively, narrowly: own .com, .net, .org, your country code, and the one or two most obvious typos. Skip the rest.
  • Keep evidence: screenshot the offending site, save WHOIS records, and note registration dates — you'll need them for a UDRP filing.

Conclusion

Cybersquatting is not one attack but four — TLD swaps, typos, combosquats, and homographs — and only the first two are worth buying your way out of. For the rest, the winning strategy is detection: enumerate your brand across every TLD, watch Certificate Transparency logs for lookalike certificates, and move fast with a UDRP complaint when you find bad-faith use. Start by running your brand through the free TLD Enumerator to see exactly which variations are already registered against you.

Frequently Asked Questions

What is cybersquatting?

Cybersquatting is registering, trafficking in, or using a domain name in bad faith to profit from someone else's trademark. It covers exact-brand squatting (registering yourbrand.co when you own yourbrand.com), typosquatting (yourbrnad.com), and combosquatting (yourbrand-login.com). In the US it is actionable under the Anticybersquatting Consumer Protection Act (ACPA); globally it is handled through ICANN's UDRP process.

Is cybersquatting illegal?

Registering a lookalike domain is not automatically a crime, but using one in bad faith to profit from a trademark is unlawful. US brand owners can sue under the ACPA (15 U.S.C. 1125(d)) for up to $100,000 in statutory damages per domain, or file a faster, cheaper UDRP complaint through WIPO or another ICANN-approved provider to have the domain transferred or cancelled without going to court.

What is the difference between typosquatting and combosquatting?

Typosquatting relies on a fat-finger error in the brand string itself, for example goggle.com or paypa1.com. Combosquatting keeps the brand spelled correctly but bolts on an extra word, such as paypal-security.com or microsoft-support.net. Combosquatting is harder to catch because the brand is intact and the added word ("login", "support", "verify") looks legitimate to users.

How does TLD enumeration help prevent cybersquatting?

TLD enumeration takes your brand string and generates every top-level variation (yourbrand.com, .net, .org, .io, .co, .app, plus country codes like .co.uk) so you can see at a glance which are registered, which resolve to live sites, and which are parked. It turns "is anyone squatting us?" into a checklist you can run on a schedule instead of discovering the lookalike only after a customer gets phished.

What is a homograph or IDN attack?

A homograph attack registers a domain using Unicode characters that look identical to Latin letters, for example a Cyrillic "а" in аpple.com. Browsers encode these as Punycode (xn--...), but the rendered address bar can look genuine. Defenses include monitoring Certificate Transparency logs for lookalikes and using browsers that display Punycode for mixed scripts.

How do I file a UDRP complaint?

File with an ICANN-approved provider such as WIPO. You must prove three things: the domain is identical or confusingly similar to your mark, the registrant has no legitimate interest in it, and it was registered and used in bad faith. UDRP cases typically resolve in about two months and cost far less than litigation, but the only remedies are transfer or cancellation, not money damages.

Should I defensively register every TLD for my brand?

No. Registering hundreds of TLDs is expensive and unnecessary. Prioritize the exact-match variants people actually type (.com, .net, .org, your country code, and the one or two obvious typos), plus any TLD tied to a scam pattern in your industry. Monitor the rest with TLD enumeration and act on real threats rather than pre-buying everything.

How do I detect cybersquatting against my brand?

Run TLD enumeration on your brand string, monitor Certificate Transparency logs for new certificates on lookalike domains, watch newly registered domain feeds for your brand keyword, and check WHOIS for privacy-shielded registrations timed near product launches. A live site plus a valid TLS certificate on a lookalike domain is a strong signal of an active phishing or squatting campaign.

cybersquattingdomain securitytyposquattingbrand protectionUDRP