
Domain Squatting
Domain squatting refers to securing internet addresses that match someone else's name or brand, usually with the intent to resell them later at a high price or to intercept visitors. Because addresses are assigned on a first-come, first-served basis, the practice is technically simple and often legally problematic.
Every website has an address you type into the browser, for example example.com. Such addresses are called domains. They are assigned according to a simple principle: whoever registers them first and pays the fee gets them. No one checks whether the name actually belongs to another company or person. This exact gap is what domain squatting exploits. Someone secures an address that is recognizably tied to someone else, then waits it out or demands money for it.
What someone else’s name in the address bar is worth
A domain often costs less than twenty euros a year. So registering a hundred addresses costs little. If just one of them later turns out to be something a company urgently needs, the whole venture can pay off. There are domains for which six- or seven-figure sums have been paid. For companies, this amounts to a small-scale extortion situation.
Even more important is the damage to trust. Whoever owns an address that looks almost like that of a well-known brand can put anything on it. Ads, dubious offers, or a deceptively authentic replica of the original site. Users rarely notice the difference, because they don’t pay attention to one or two letters. That’s how a naming dispute quickly turns into a security problem.
For the AI industry, this topic has been especially prominent for a few years now. New product names pop up there on a weekly basis. Barely has a model or a start-up been announced, and the matching addresses are already taken. Some providers therefore pay large sums just to be reachable under their own name at all.
From typos to expired addresses
The simplest variant is pure waiting. Someone registers a name they believe a company will soon need. This often happens right after a press release or a patent application in which a new product name appears. Some squatters search such sources automatically and register at a rate of minutes.
A second variant is called typosquatting and targets typing errors. Instead of the real address, a slightly altered version is secured, for instance with swapped letters or a missing suffix. Anyone who mistypes ends up with the squatter. Related to this is the trick using characters that look almost identical, for example a capital I instead of a lowercase l.
A third variant exploits negligence. Domains must be renewed annually. If an owner forgets to pay, the address becomes available again. Specialized services monitor thousands of expiring domains and grab them the moment they become available. This should not be confused with normal domain trading: buying a generic term like travel.com is legitimate, whereas deliberately grabbing someone else’s brand name is not.
Disputes, protective measures, and what users can do
Affected companies don’t have to go to a regular court. For domain disputes there is a dedicated arbitration procedure called UDRP, introduced by the internet governing body ICANN. An arbitration panel examines three points: does the domain resemble a protected brand, does the holder lack any legitimate interest in it, and did they act in bad faith? If all of this applies, the address is transferred. Such proceedings take weeks instead of years.
Companies also take preventive measures. They register dozens of variants of their main name right away, with different suffixes and typical typos. This is cheaper than a later legal dispute. Major brands additionally monitor whether new addresses containing their name appear anywhere.
In everyday life, you’re most likely to encounter domain squatting as a security risk. Fake shops, phishing emails with an almost genuine sender address, or download pages for supposedly well-known programs frequently run through such domains. The best protection is unspectacular: type addresses yourself or open them from bookmarks instead of following links from messages. And if a page seems odd, it’s worth taking a close look at every single letter in the address bar.