Cybersecurity glossary

What is Combosquatting?

Learn what combosquatting is, how attackers combine trusted brands with lure words, and why combosquatting often evades simple typo-distance monitoring.

DNS and infrastructureUpdated July 23, 2026
Also known asBrand-plus-keyword squattingKeyword-assisted squattingSemantic lookalike domain abuse

Definition

Combosquatting is the registration of a domain that combines a trusted brand or keyword with additional words such as login, support, billing, or secure in order to create a convincing but fraudulent domain name.

Why combosquatting is so effective

A combosquatting domain does not need to be one character away from your brand to work. It can be far more believable if it sounds like a real workflow: brand-login, brand-billing, brand-support, or brand-mail often look more legitimate in an inbox than a raw typo ever would. That is why combosquatting slips past narrow typo monitors. The attacker is not imitating your spelling; they are imitating your business language, support vocabulary, and the actions users expect to take around your brand.

What attackers exploit in combosquatting

Exact brand token

The trusted brand often appears intact, which makes the domain feel official at first glance.

Lure word appendage

Additional words such as login, secure, verify, mail, or account create a workflow cue that pushes urgency or legitimacy.

Wide domain availability

Many semantic combinations remain unregistered even when the obvious typo variants are already claimed or monitored.

Campaign flexibility

The same domain pattern can support phishing, fake support, invoice fraud, ad abuse, or affiliate monetization.

How a combosquatting campaign is built

1

Select a trusted brand

The attacker starts with a company, product, or service users already recognize and act on quickly.

2

Choose persuasive companion words

Keywords such as login, portal, support, billing, or verify are added to create a believable purpose.

3

Register the available combinations

The attacker acquires domains across one or more TLDs that fit the intended lure theme.

4

Stand up a themed landing page

The site imitates the visual language of the brand and asks the victim to sign in, pay, or download something.

5

Distribute the domain through trust channels

Email, SMS, search ads, social outreach, or fake support messages deliver traffic to the site.

6

Harvest credentials or money

The attacker captures passwords, MFA codes, payment data, or support fees before the domain is discovered.

How combosquatting differs from neighboring threats

The distinction matters because each family of lookalike abuse requires different detection logic.

ElementWhat it meansWhy it matters
CombosquattingThe domain combines a trusted brand with extra words that suggest a business workflow or support action.Defenders need semantic brand monitoring, not just typo distance or Unicode checks.
TyposquattingThe malicious name is close because of spelling mistakes, transpositions, or alternate TLD choices.Edit-distance and typo dictionaries are more useful here than brand-keyword analytics.
CybersquattingThe registration is tied to trademark exploitation, resale, or bad-faith brand capture more broadly.Legal and brand-protection remedies often play a larger role in response.
Homograph abuseThe label relies on visually confusable characters across scripts rather than appended lure words.Script analysis and [Punycode](/glossary/punycode) inspection are more relevant for that class.

Combosquatting defenses that work better than typo-only monitoring

Because the deception is semantic, defenders need to watch language patterns as well as spelling patterns.

  • Monitor brand-plus-keyword combinations around login, support, billing, mail, portal, update, verify, and executive communication themes.
  • Search certificate transparency, search-engine ads, and phishing telemetry for domains that pair your brand with action words.
  • Publish an official list of login, billing, and support URLs so users can compare suspicious links against a known-good set.
  • Use [DMARC](/glossary/domain-based-message-authentication-reporting-and-conformance-dmarc), [SPF](/glossary/sender-policy-framework-spf), and [DKIM](/glossary/domainkeys-identified-mail-dkim) so spoofed email has a harder time delivering combosquat lures from your own domain.
  • Coordinate brand monitoring with customer support and fraud teams because many combosquat domains mimic real support workflows.
  • Consider defensive registration for the most obvious brand-plus-keyword combinations that would be costly if abused.
  • Watch paid search, marketplace listings, and social profiles because attackers often pair combosquat domains with off-domain promotion.
  • Classify [typosquatting](/glossary/typosquatting) and combosquatting separately in reporting so your detection gaps are visible.

Combosquatting abuses business context

The strongest combosquatting domains sound like something your users already expect to click. That is why they often outperform clumsy typo domains in phishing and support scams: the name mirrors the task, not just the brand. For defenders, that means brand protection cannot live only in DNS engineering. It has to absorb knowledge from marketing copy, support workflows, billing language, and the names of real customer journeys attackers are trying to imitate.

The practical takeaway

Combosquatting is the use of brand-plus-keyword domains to create convincing fraudulent names such as brand-login or brand-support. The practical takeaway is to monitor semantics, not just spelling. If your detection only asks “Is this a typo?”, many of the most believable phishing domains will look invisible until after they are used.

Related security terms

Frequently asked questions

What is combosquatting in simple terms?

It is when someone registers a domain like `brand-login` or `brand-support` to make it sound official and trustworthy.

How is combosquatting different from typosquatting?

Typosquatting is close by spelling. Combosquatting is close by meaning and context, often with no typo at all.

Why do attackers like combosquatting?

Because many useful brand-plus-keyword combinations are still available and look plausible in email, ads, and chat messages.

Is combosquatting always phishing?

Phishing is common, but the domains may also be used for affiliate fraud, malware downloads, fake customer support, or parked trademark abuse.

Can simple edit-distance alerts catch combosquatting?

Not reliably. The malicious name may share the brand exactly and just append extra words that a distance-based detector treats as far away.

What words are most abused in combosquatting?

Words like login, secure, support, verify, billing, portal, mail, update, and account are frequent because they imply urgency or authority.

References

Explore authoritative guidance and frameworks related to combosquatting.

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary