“Register everything” sounds thorough and is arithmetically impossible. Working the numbers once is the fastest way to end the conversation and redirect the budget.
The numbers
Single-label permutations of a 9-character brand
(omission, transposition, insertion, substitution,
repetition, vowel swap, homoglyph, hyphenation)
~1,500 - 2,500
x the TLDs a customer might plausibly use
x 10 -> ~20,000
Combosquats: brand + any word
a 5,000-word practical vocabulary
x 2 positions (prefix and suffix)
x 10 TLDs -> 100,000
At $10/year: $1,200,000 per year
forever
for one brandAnd the space is still incomplete: two-word combosquats, other scripts, and every new TLD that launches. There is no value of “everything” that terminates.
What it displaces
- Detection. A fraction of that budget buys monitoring that covers the whole space rather than a slice of it.
- Response capacity. Takedown is the lever that compresses the earning window, and it is people rather than registrations.
- User-facing controls. Payment verification and external-sender warnings address the techniques registration cannot touch at all.
- Attention. Every held domain needs renewal, records and an owner. Fifty is a programme; five hundred is a liability.
How to put it
Not “that is too expensive”, which invites a smaller version of the same idea. The space has no boundary, so any registration budget buys an arbitrary fraction of it while an attacker needs one name you did not buy. The same money spent on detecting and removing them applies to all of it.
Hold a small, defensible set
The primary brand in the TLDs customers use, single-character errors on the primary brand, and anything already used against you. Written down, with the rationale, and reviewed annually. That is a policy; “register everything” is an aspiration with an unbounded invoice.