Glossary
Attacks
Typosquatting
Registering domains that are plausible mistypings of a target — omitted, doubled, transposed or adjacent characters. It relies on the victim making the error rather than on being deceived by the name.
Defined in M3AAWG best practice.
Where this appears
The lessons that use this term, and what each is for.
Domain Security FundamentalsHow lookalike domains are generatedClassify a lookalike domain by the technique used to produce it.Domain Security FundamentalsScoping monitoring so it produces actionDefine a monitoring scope you can actually act on, and justify what you excluded.Domain Abuse & ImpersonationThe attacker’s arithmeticState what a lookalike campaign costs to run, and what it has to return to be worth running.Domain Abuse & ImpersonationThe lifecycle of a phishing domainPlace a domain on its timeline from registration to abandonment, and say what that implies for response.Domain Abuse & ImpersonationGenerating the spaceProduce the complete permutation set for a brand, and say how large it is before you cut it.Domain Abuse & ImpersonationCutting it to what mattersReduce a permutation space of thousands to a watchlist you would actually act on.Domain Abuse & ImpersonationFour outcomesPlace any suspicious domain into one of four categories from the evidence available.Brand ProtectionWhen holding a name pays for itselfDecide whether a specific defensive registration is worth its annual cost.Brand ProtectionThe arithmetic against registering everythingShow why a register-everything policy cannot be completed, and what it displaces.Domain Security PractitionerThe impersonation exposureQuantify what is being registered against the brand using only public data.