Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
urlcrazy — Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage. | Kitploit
Tools/GitHubGitHub/urbanadventurer/urlcrazy
OSINT (Open Source Intelligence)Information GatheringPhishingPenetration TestingDNS Analysis
GitHuburbanadventurer/urlcrazy

urlcrazy

Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.

View Repository
692107251 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

License Stable Release Repositories

😜⌨ URLCrazy

URLCrazy is an OSINT tool to generate and test domain typos or variations to detect or perform typo squatting, URL hijacking, phishing, and corporate espionage.

Homepage: https://github.com/urbanadventurer/urlcrazy

🌟 Use Cases

  • Detect typo squatters profiting from typos on your domain name
  • Protect your brand by registering popular typos
  • Identify typo domain names that will receive traffic intended for another domain
  • Conduct phishing attacks during a penetration test

⭐ Features

  • Generates 17 types of domain variants
  • Knows over 8000 common misspellings
  • Over 1500 Top Level Domains supported
  • Bit-flipping attacks
  • Multiple keyboard layouts (QWERTY, AZERTY, QWERTY, DVORAK)
  • Checks if a domain variant is valid
  • Test if domain variants are in use
  • Estimate popularity of a domain variant

🛠 Installation

Install from a package manager

If you are using Kali Linux, Ubuntu or Debian use:

$ sudo apt install urlcrazy

Install latest release

Visit https://github.com/urbanadventurer/urlcrazy/releases

Install current development version

Be aware the latest development version may not be stable.

$ git clone https://github.com/urbanadventurer/urlcrazy.git

Install Ruby

URLCrazy has been tested with Ruby versions 2.4 and 2.6.

If you are using Ubuntu or Debian use:

$ sudo apt install ruby ruby-dev build-essential

Install Bundler

Bundler provides dependecy management for Ruby projects

$ gem install bundler

Install Dependencies

$ bundle install

Alternatively, if you don't want to install bundler, the following command will install the gem dependencies.

$ gem install json colorize async async-dns async-http

💻 Usage

urlcrazy-usage

Simple Usage

With default options, URLCrazy will check over 2000 typo variants for google.com.

$ urlcrazy google.com

urlcrazy-google

With popularity estimate

$ urlcrazy -p domain.com

Commandline Usage


db    db d8888b. db       .o88b. d8888b.  .d8b.  d88888D db    db
88    88 88  `8D 88      d8P  Y8 88  `8D d8' `8b YP  d8' `8b  d8'
88    88 88oobY' 88      8P      88oobY' 88ooo88    d8'   `8bd8'
88    88 88`8b   88      8b      88`8b   88~~~88   d8'      88
88b  d88 88 `88. 88booo. Y8b  d8 88 `88. 88   88  d8' db    88
~Y8888P' 88   YD Y88888P  `Y88P' 88   YD YP   YP d88888P    YP

URLCrazy version 0.8.1 by Andrew Horton (urbanadventurer)
Visit https://github.com/urbanadventurer/urlcrazy

Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking,
phishing, and corporate espionage.

Supports the following domain variations:
Character omission, character repeat, adjacent character swap, adjacent character replacement, double
character replacement, adjacent character insertion, missing dot, strip dashes, insert dash,
singular or pluralise, common misspellings, vowel swaps, homophones, bit flipping (cosmic rays),
homoglyphs, domain prefix, domain suffix, wrong top level domain, and wrong second level domain.

Usage: ./urlcrazy [options] domain

Options
-k, --keyboard=LAYOUT  Options are: qwerty, azerty, qwertz, dvorak (default: qwerty)
-p, --popularity       Check domain popularity with Google
-r, --no-resolve       Do not resolve DNS
-i, --show-invalid     Show invalid domain names
-f, --format=TYPE      Human readable, JSON, or CSV (default: human readable)
-o, --output=FILE      Output file
-n, --nocolor          Disable colour
-d, --debug            Enable debugging output for development
-h, --help             This help
-v, --version          Print version information. This version is 0.7.3

🔦 Types of Domain Variations Supported

Character Omission

These typos are created by leaving out a letter of the domain name, one letter at a time. For example, www.goole.com and www.gogle.com

Character Repeat

These typos are created by repeating a letter of the domain name. For example, www.ggoogle.com and www.gooogle.com

Adjacent Character Swap

These typos are created by swapping the order of adjacent letters in the domain name. For example, www.googel.com and www.ogogle.com

Adjacent Character Replacement

These typos are created by replacing each letter of the domain name with letters to the immediate left and right on the keyboard. For example, www.googke.com and www.goohle.com

Double Character Replacement

These typos are created by replacing identical, consecutive letters of the domain name with letters to the immediate left and right on the keyboard. For example, www.gppgle.com and www.giigle.com

Adjacent Character Insertion

These typos are created by inserting letters to the immediate left and right on the keyboard of each letter. For example, www.googhle.com and www.goopgle.com

Missing Dot

These typos are created by omitting a dot from the domainname. For example, wwwgoogle.com and www.googlecom

Strip Dashes

These typos are created by omitting a dash from the domainname. For example, www.domain-name.com becomes www.domainname.com

Singular or Pluralise

These typos are created by making a singular domain plural and vice versa. For example, www.google.com becomes www.googles.com and www.games.co.nz becomes www.game.co.nz

Common Misspellings

Over 8000 common misspellings from Wikipedia. For example, www.youtube.com becomes www.youtub.com and www.abseil.com becomes www.absail.com

Vowel Swapping

Swap vowels within the domain name except for the first letter. For example, www.google.com becomes www.gaagle.com.

Homophones

Over 450 sets of words that sound the same when spoken. For example, www.base.com becomes www.bass.com.

Bit Flipping

Each letter in a domain name is an 8bit character. The character is substituted with the set of valid characters that can be made after a single bit flip. For example, facebook.com becomes bacebook.com, dacebook.com, faaebook.com,fabebook.com,facabook.com, etc.

Homoglyphs

One or more characters that look similar to another character but are different are called homogylphs. An example is that the lower case l looks similar to the numeral one, e.g. l vs 1. For example, google.com becomes goog1e.com.

Wrong Top Level Domain

For example, www.trademe.co.nz becomes www.trademe.co.nz and www.google.com becomes www.google.org Uses the 19 most common top level domains.

Wrong Second Level Domain

Uses an alternate, valid second level domain for the top level domain. For example, www.trademe.co.nz becomes www.trademe.ac.nz and www.trademe.iwi.nz

Domain Prefix

These typos are created by adding a prefix from the prefix-dictionary.txt file with a hyphen to the domain name. For example, example.com becomes login-example.com and corp-example.com

Domain Suffix

These typos are created by adding a suffix from the suffix-dictionary.txt file with a hyphen to the domain name. For example, example.com becomes example-login.com and example-microsoft.com

⌨ Supported Keyboard Layouts

Keyboard layouts supported are:

  • QWERTY
  • AZERTY
  • QWERTZ
  • DVORAK

🕯 Is the domain valid?

Download Tool