You’re a security researcher trying to do the right thing: report a crime to the FBI’s Internet Crime Complaint Center. You type the address from memory. One tiny mistake, ic3.org instead of ic3.gov, and suddenly the internet has decided you’re not reporting cybercrime anymore. You’re traffic.
On mobile, that innocent-looking typo whisks you off to a fake warning about your cloud storage subscription expiring (because of course it does). Meanwhile, automated scanners see a boring old parking page and shrug.
It’s a tiny, perfect case study in the weird business of catching people who mistype URLs, figuring out if they’re worth anything, and then selling that fleeting moment of confusion to the highest bidder via ads and affiliate links. The internet, everybody.
Typosquatting is as old as the commercial web itself. But once automated advertising emerged, it went from a minor annoyance to a full-blown industry. Now, a single typo can turn into an ad impression, a click, an affiliate payout, or an open door for ad fraud.
That being said, the game is shifting again. Google finally kicked parked domains out of its Search Partner Network (RIP, February 2026), shutting down one of the main highways for this kind of activity. Naturally, typo traffic is already finding new, shadier routes—like these so-called ‘direct search’ systems that can drop you straight into an ad, a scam, or a malware pit.
Which leaves us with the question digital advertising finds hard to answer: what exactly are we supposed to do when a ‘real’ visitor only landed on your site because they were confused? Is that a win? Or another weird internet tax?
How a Typo Becomes Advertising Inventory
Typosquatting is the art (if you can call it that) of grabbing a domain that looks almost, but not quite, like a real one. Maybe you drop a letter, double one up, swap two around, or swap .com for .co and hope nobody notices. If you’re feeling fancy, you can even throw in a sneaky Unicode character or tack on words like “login,” “support,” or “secure” to make it all look extra legit. The creativity here is… honestly, kind of impressive, if also deeply annoying.
And then, of course, the person who owns the domain sits back and waits for the accidental tourists to show up—cha-ching.
The standard playbook is to point the typo domain at a parking service. The service then builds a page of search links or ads, usually based on the keywords the domain name suggests. When someone clicks, the advertiser pays the syndicator, which takes its cut before passing money along to the parking company and the domain owner. The whole setup is a Rube Goldberg machine for squeezing pennies out of people’s mistakes.

The whole thing runs on autopilot. Nobody’s out there pitching each sad little typo domain to advertisers one by one. You plug your thousand-strong portfolio into a parking company and let the ad demand flow in.
That automation was transformative. Researchers Tyler Moore and Benjamin Edelman estimated in 2010 that at least 938,000 typo domains targeted 3,264 popular .com websites. After crawling more than 285,000 domains, they found that “80% are supported by pay-per-click ads.” Their research also found that typo domains frequently advertised the correctly spelled site or one of its competitors.
Research · Domain abuse
The economics of typosquatting: how a single misspelled click becomes ad revenue
After crawling more than 285,000 domains, researchers found that “80% are supported by pay-per-click ads.”
Source: Tyler Moore & Benjamin Edelman, “Measuring the Perpetrators and Funders of Typosquatting,” 2010.
The money side of this is weirdly concentrated. Of all the typo domains running Google ads, nearly two-thirds were tied to just five publisher IDs. So, all that sprawling mess of sketchy domains turns out to be mostly powered by a handful of big players behind the curtain.
A Business Built on Misdirected Intent
Search ads work because, at their core, they’re eavesdropping on what you want—typed straight into the box. Turns out, even a clumsy typo in a domain bar is you waving a little flag that says, ‘Hey, I’m looking for something.’
If you’re typing ‘Expedia’ but end up with ‘Expeida’—congrats, you’ve broadcast your travel plans to the universe. Misspell your bank’s name, and suddenly, you’re radiating financial intent. Fumble a retailer’s URL, and you’re holding up a neon sign that says, ‘I’m ready to buy, please sell me something.’
And the wild part is that intent gets packaged up and sold, even if you never meant to land on the typo in the first place. Oops, your attention is now on inventory.

Back in 2015, some researchers at KU Leuven and Stony Brook University went down the rabbit hole and looked at over 8 million parked domains (yes, eight million). Out of a sample of 3,000, just 4 ad syndicators showed up on 91% of them. Google’s Ad Manager and AdSense were everywhere, like glitter after a craft project. Their conservative estimate was 131,673 typo domains. And that’s what the robots could find.
Manual review (aka, actual humans squinting at spreadsheets) suggested the automated count was almost charmingly optimistic: about 16% of those parked domains looked like typosquatting or trademark shenanigans.
For extra credit, the researchers registered a misspelled version of Stack Overflow (with permission, don’t worry) and tried to park it with a bunch of services. Every single one said, ‘Sure, come on in.’ Not a single eyebrow raised.
To be fair, not every parked domain is evil. Some are expired, some are defensive, some are projects that never quite made it out of the idea phase. But the experiment did show how little resistance there is when you try to sneak an obvious typo into the ad machine. It’s almost too easy.
Typosquatting Is Not Domain Spoofing
Advertising fraud terminology is, frankly, complicated. Typosquatting gets lumped in with domain spoofing, affiliate hijacking, malvertising, and those made-for-advertising sites—like we’re all playing buzzword bingo. Sure, some of these overlap, but they’re not the same thing.
Typosquatting is the classic move: someone grabs a lookalike domain and waits for the inevitable typo traffic to roll in.
Domain spoofing is a bit more devious: a seller fiddles with the ad bid request so that junk inventory suddenly looks like it’s coming from a fancy publisher. Advertisers think they’re getting prime real estate on a big-name news site, but their ad is off in the digital wilderness somewhere.
Affiliate hijacking is when a partner swoops in and claims credit for a sale that was probably going to happen anyway—maybe by bidding on your brand’s search terms, impersonating your ad, or sneakily routing traffic through their affiliate link. Sometimes they use a typo domain for extra flair, but honestly, they don’t even need it.
Malvertising is what it sounds like: malicious advertising or redirects. It can come from a typo domain, a compromised legit site, or your run-of-the-mill ad exchange. Pick your poison.
These distinctions matter. The industry’s defenses are only useful if you know which flavor of scam you’re dealing with. Otherwise, it’s whack-a-mole with extra steps.
Why Can ads.txt Not Answer the Trademark Question
In 2017, the digital ad world rolled out ads.txt (yes, another file to manage) so publishers could publicly declare which companies were allowed to sell their stuff. Then came sellers.json and the OpenRTB SupplyChain object, which—at least in theory—let buyers trace who was involved in any given transaction. So, a whole lot of files and IDs, all in the name of cleaning up the mess.
The stated mission of ads.txt is to “increase transparency in the programmatic advertising ecosystem.” According to IAB Tech Lab, the standard makes it harder to sell counterfeit inventory under a participating publisher’s identity.
That’s genuinely useful if you’re worried about domain spoofing. But it is not so much when it comes to typosquatting.
A typo domain can slap up a perfectly valid ads.txt file, give the green light to an exchange, and—voilà—everything looks legit on paper. The exchange might really represent that domain, and all the seller IDs might check out. But nowhere in that file does it say, ‘By the way, I actually own this brand,’ or ‘People meant to land here,’ or even ‘This isn’t a sneaky lookalike of a real site.’
So, ads.txt tells you who’s allowed to sell the ads. It does not, sadly, vouch for whether the publisher is legit or a typo-ridden imposter.
You see the same blind spot in how we measure invalid traffic. Sure, fraud systems are great at catching bots, fake impressions, and click farms. But if a real human fumbles a URL, lands on some random parking page, and clicks an ad? That’s probably going to pass every test with flying colors.
The traffic is technically human. However, the way it got there is the actual problem.
The Numbers Are Large and Easy To Misuse
So, apparently, if you want to feel slightly overwhelmed, look at the latest typosquatting study from 2025. The researchers (Wisconsin, Boston, Colgate) went full data-hoarder mode: they spun up variants of 721 top domains and then trawled through 3.3 billion DNS and certificate records. Three. Point. Three. Billion. I mean, sure, why not?
That left over 2.3 million candidate domains that resolved somewhere. Roughly 558,000 were parked, basically idling on the internet like digital tumbleweeds. The rest were a mix of defensive registrations, random legit sites, and more than a million domains that don’t even bother to show you a web page.
What often gets lost in the panic is that a domain resembling a famous brand is not automatically a scam. It might be unused, registered defensively, legitimate in some oddly specific context, or part of someone’s internal setup. Automated tools can flag patterns, but they cannot explain intent.
Out of all that, the study flagged 3,727 domains via Google Safe Browsing and linked another 2,012 to malicious stuff. Which, if you’re keeping score, is a tiny fraction compared to the sea of parked and mystery domains.
There’s no need to panic every time someone registers a typo domain. Most remain unused or prove harmless. The problem is scale: even if only a tiny share is malicious, that still leaves thousands of active threats to monitor.
From Parking Pages to Invisible Auctions
Remember when parked domains used to sit there, quietly displaying a sad little grid of sponsored links? Well, the new version doesn’t even bother pretending. Sometimes there’s no page at all.
Enter “direct search” (or, if you’re feeling fancy, zero-click parking): now your traffic gets sold off straight away. Ad networks and traffic brokers size up your domain, your location, your device, your browser, your network—basically everything short of your astrological sign—before deciding where to send you. And the best part? You can get shuffled through a whole daisy chain of resellers without ever clicking a thing.
On paper, this is supposed to boost conversion rates by skipping the awkward middleman step. In reality, it also makes the whole process about ten times harder to trace.
In its December 2025 investigation, Infoblox reported that approximately 90% of the direct-search visits it tested ended at scams, malware, or other unwanted content. The company said “malicious content is the norm” within the activity it examined. Its report documented domains that showed harmless pages to scanners or non-residential connections while redirecting ordinary mobile users elsewhere.
Before you start panicking, that 90% number needs a little context. It doesn’t mean 90% of all parked domains are evil. It’s what Infoblox found in their particular slice of direct-search traffic. And, as usual, the report is a bit vague on how representative that slice is.
Also, to be fair, Infoblox isn’t saying the parking companies or ad platforms themselves are running these scams. The sketchy stuff usually pops up a few resales down the line, well past the point where anyone wants to take responsibility.
And that’s kind of the whole problem. Responsibility gets passed around like a hot potato. The domain owner has no idea who’s advertising. The advertiser has no clue where their traffic is coming from. Everyone shrugs and points to the next link in the chain.
Google Shuts the Door on Parked-Domain Ads
So, for what feels like forever, Google let search ads show up on parked domains via its Search Partner Network. Yes, that means you could pay actual money every time someone clicked an ad on a page that was simply… nothing.
In 2024, Google finally started to back away from this arrangement. New accounts were opted out by default (progress!), and by 2025, the opt-out got bigger. Eventually, Google declared that parked domains “will cease to be an ad surface” in the partner network. Cue the tiny violin for all those empty pages losing their ad budgets.
The change actually landed on February 10, 2026. If you check Google’s policy page, you’ll see the option to include parked domains has quietly vanished from account settings. Poof.
Meanwhile, in 2025, Google rolled out more detailed site-level placement reporting for Search Partner traffic. Finally, advertisers could see where their campaigns showed up, instead of squinting at a big, blurry blob of “partner network” data and hoping for the best. This was, you know, a problem for only about a decade.
So, in theory, less mainstream ad money should end up on classic parked pages now. But let’s not get too excited: typo traffic is still alive and well, and plenty of other networks are happy to scoop it up.
Infoblox thinks stricter mainstream policies might be nudging some domain owners toward direct-search systems. Maybe! It’s plausible, but not exactly proven. Lower parking revenue, security dodges, and the never-ending hunger of aggressive affiliate networks are probably all in the mix, too.
The real risk here is displacement. Cleaner platforms pat themselves on the back, but the traffic doesn’t disappear—it finds a new home with intermediaries who care a lot less about controls.
The Accountability Gap
Typosquatting is the digital ad industry’s recurring nightmare—because, for all our talk about verification and transparency, we’re still much better at rubber-stamping transactions than asking how (or why) the opportunity even exists in the first place.
You can have an authorized seller. You can have a fully disclosed supply chain. The visitor? Definitely human. The click? Real, apparently. And yet, the whole thing can still hinge on someone being misled. Love that for us.
Closing that gap? It’s going to take more than tossing another blocklist onto the pile. Sure, ad platforms could check if publishers look suspiciously like established brands (wild idea, I know). Parking services could try visiting destinations from real devices to see what’s there. Affiliate programs could, in theory, ban brand misspellings and look at redirect chains. Advertisers could even—brace yourself—ask for placement-level logs and refunds when traffic turns out to be, well, a little too creative. But, as usual, most of this gets filed under ‘nice in theory, exhausting in practice.’
Brands also need to distinguish trademark enforcement from security response. A parked domain carrying ads may require a UDRP complaint; a phishing site should be reported immediately to registrars, hosting providers, browsers, and security services. Evidence should include timestamps, screenshots, DNS records, ad identifiers, and complete redirect chains.
Defensive registration can protect the most likely variants, but purchasing every possible misspelling is neither practical nor permanent. The 2025 research showed how quickly the namespace expands when alternative suffixes and combined words are included.
A Typo Is Tiny. Blink, and You Miss It.
A stray typo is easy to understand. Building a revenue stream around it is much harder to defend.
The history of typosquatting is often told as a story about careless users and opportunistic domain owners. That framing misses the machinery that made the practice durable.
Turns out, a misspelled URL is like a little gold nugget if you have the right ad system. The machines spot the intent, find someone willing to pay for it, and then everyone in the chain gets their cut. Confusion becomes inventory, like magic—except the magic is relentless automation.
So, Google finally steps away from parked-domain ads. Big moment, right? Except, of course, the internet is nothing if not creative at finding new ways to keep the money flowing. Enter direct-search networks. The lesson: money and traffic don’t disappear; they sneak off to the next available loophole.
Maybe the real test for advertising is not just, “Was this a real person?” It is, “Did that person understand where they had ended up?” And more importantly, did anyone profiting from that moment bother to check?
