Skip to main content

Combosquatting

Combosquatting combines a brand name with an extra word, such as "paypal-security.com" or "apple-support.net", to create a domain that looks legitimate and trustworthy.

How it works

Unlike typosquatting, the brand name is spelled correctly, so it passes a quick glance. Attackers append words like "login", "secure", "support", "wallet", or "pay" that fit the pretext of the scam, then host phishing or fraud on the result.

How it relates to brand impersonation

Because the brand name stays intact, combosquatting is especially convincing in emails and ads. That makes it a favourite for spear phishing and support scams that impersonate your brand.

How nebty helps

nebty monitoring watches the keyword-combination space around your brand, not just simple typos, so support- and payment-themed lookalikes surface early and can be taken down on demand.

Domain monitoring

Why combosquats slip past people

Combosquatting is dangerous precisely because nothing is misspelled. A domain like yourbrand-support.com or secure-yourbrand.com contains your exact name, so it passes the quick scan most people give a link, and it reads as plausible in an email signature or an ad. The added word is chosen to fit the pretext: support, help, and account for service scams; secure, verify, and login for credential theft; pay, wallet, and refund for payment fraud. There is no limit to the combinations, so defensive registration cannot cover them all. The practical defence is monitoring that watches keyword combinations around your brand, not single-character typos alone, and scores the payment- and login-themed ones as higher risk so they reach a human before customers do.

Treat any combosquat that has set up mail records as urgent, since that is the step taken right before it starts sending invoices or support messages in your name.

A concrete example

Someone registers solara-finance-support.com, a combination of the brand Solara Finance and the word "support". For a week nothing happens. Then the domain gets mail records, and customers start receiving "your account has been limited" emails from [email protected] with a link to a fake login. Nothing in the address is misspelled, so the emails read as legitimate. Keyword monitoring had flagged the registration on day one; the mail records were the signal to escalate it to a takedown.

How to spot and stop it

  1. Monitor keyword combinations around your brand name, not just single-character typos. The dangerous words are predictable: support, secure, login, verify, pay, refund.
  2. Treat any combosquat that sets up mail (MX) records as urgent. That step usually comes right before invoice or support fraud starts.
  3. Check links by reading the registered domain, the part directly before the ending. "solara-finance-support.com" is not "solarafinance.com", however plausible it sounds.

Frequently asked questions

What is the difference between combosquatting and typosquatting?

Typosquatting misspells the brand name and catches people who mistype or misread. Combosquatting spells the name correctly and adds a word, so it deceives even careful readers who check that the brand is in the address.

Is a combosquatting domain illegal?

Registering one is not automatically a crime, but using a protected brand name to deceive supports trademark claims, UDRP proceedings, and abuse reports. In practice, fraudulent use gives you solid grounds for a takedown.

Can I just register all the combinations myself?

No. With every keyword, hyphen variant, and ending, the combination space runs into the millions. Defensive registration covers a handful of obvious names; monitoring covers the rest.

See who is impersonating your brand

The free nebty report scans the web for lookalike domains and fake profiles targeting your brand, with no obligation.

Get your free report