Email typo domains: catch gmial.com and suggest the fix

Email typo detection compares the domain with popular providers and offers a fix, like gmial.com to gmail.com. How it works, what typos cost, how to show it.

  • #signup
  • #free-email
  • #engineering
  • #api
A sign-up field containing jane@gmial.com with the hint Did you mean jane@gmail.com?, buttons to use the suggestion or keep the address as typed, and a diff showing the swapped letters. Create your account Work email jane@gmial.com i Did you mean jane@gmail.com? Use jane@gmail.com Keep as typed // 1 edit: swap - jane@gmial.com + jane@gmail.com

Email typo detection catches sign-ups like jane@gmial.com, where the domain is one slip of the keyboard away from a popular provider, and offers the fix: “Did you mean jane@gmail.com?” It works by comparing the domain with a list of providers and counting the single-character edits between them. Show the result as a one-click suggestion next to the field, and never change what the person typed without asking.

How provider typos happen

Nobody types gmial.com on purpose. Provider typos come from a handful of mechanical slips, and each one changes the domain by a single character or a single swap:

Slip Typed Meant
Two letters swapped gmial.com, hotmial.com gmail.com, hotmail.com
Neighboring key gnail.com, hotmaul.com gmail.com, hotmail.com
Letter missing gmai.com, outlok.com gmail.com, outlook.com
Letter doubled gmaill.com, yahooo.com gmail.com, yahoo.com
Ending slipped gmail.con, hotmail.cmo, yahoo.co gmail.com, hotmail.com, yahoo.com

A few things make them more likely on sign-up forms in particular:

  • Typing fast on a phone. Small keys put n next to m and o next to i, and few people proofread an email field.
  • Muscle memory. People type their own address fast, without looking.
  • Autofill repeats mistakes. Once a browser or password manager saves a mistyped address, it offers it again on the next form.
  • The domain gets less attention than the name. People check that jane.doe is right and rarely look again at what follows the @.

How often it happens depends on your audience and your form, so measure it on your own sign-ups; the last section shows how.

What a typo costs

The quiet costs are the worst ones, because the mistyped address is accepted and looks almost right.

The confirmation email never arrives

The person waits for the activation link, doesn’t get it, and decides your product is broken. They try again with the same autofilled typo, or leave, or open an “I never got the email” ticket.

Bounces count against your sender reputation

If the typo domain has no mail servers, every message to it bounces. Mailbox providers and email service providers watch bounce rates, and a steady flow of hard bounces counts against your sending domain, which can push the rest of your mail toward spam folders.

Some typo domains receive the mail

Typo domains of big providers attract registrants, and some are owned by people who aren’t the provider. A typo domain set up to accept mail for any address quietly receives what your users meant to send to themselves: welcome emails, invoices, password resets. Some typo domains are also run as spam traps, so mailing them marks you as a sender who doesn’t clean its list.

If your product lets someone use the account before confirming the address, the risk goes further: whoever controls the typo domain can request a password reset for jane@gmial.com and take over the account. Require the confirmation email before the account does anything that matters.

How isBusinessEmail detects typos

isBusinessEmail compares the domain with a short list of popular providers: gmail.com, yahoo.com, hotmail.com, outlook.com, icloud.com, aol.com, proton.me, gmx.de, web.de, yandex.ru, qq.com, naver.com, ISP domains such as comcast.net, and a few more. The free email providers list is far longer; the typo list holds only the providers people type often enough to mistype.

Edit distance that counts a swap as one edit

The comparison uses optimal string alignment distance, a variant of Damerau-Levenshtein distance. It counts the smallest number of edits that turn one domain into the other, where an edit is inserting, deleting or replacing one character, or swapping two neighboring characters. Plain Levenshtein distance counts a swap as two edits; here gmial.com is one edit from gmail.com, which matters because swaps are the classic fast-typing slip.

The rules:

  1. One edit from a provider is a likely typo. gmial.com, gnail.com, gmai.com and gmaill.com all suggest gmail.com.
  2. Two edits count only when the provider’s domain is at least nine characters long and the typed domain has the same ending. hotnial.com is two edits from hotmail.com and gets the suggestion. The same-ending rule exists because short domains with different endings are often different, real providers: gmx.at is not a typo of gmx.de, and proton.ch is not a typo of proton.me.
  3. Very short domains, under six characters in total, skip the edit-distance step. At that length one edit turns almost any domain into a different one.
  4. When several providers are within reach, the closest wins, and a tie goes to the more popular provider.

Ending slips: .con, .cmo and friends

Before the distance check, a small table fixes common slips in the ending: .con, .cmo, .ocm, .vom, .xom, .comm, .cm, .co and .om become .com, and .nte, .ner and .ent become .net. The fix is only suggested when the result is one of the providers, so gmail.con and hotmail.cmo get gmail.com and hotmail.com, while acme.con gets nothing. This step also covers short domains: me.cm suggests me.com.

Real companies on similar-looking domains

Some companies run on a domain one letter away from a provider. Flagging their staff would be a costly false positive, so the suspicion is cleared when the domain’s DNS shows strong evidence of an organization:

  • Google Workspace or Microsoft 365 mail servers in MX
  • an email security gateway, such as Proofpoint or Mimecast, in MX
  • domain-verification tokens for business SaaS in TXT records
  • a Microsoft Entra tenant for the domain
  • business sending services in SPF together with an enforcing DMARC policy (quarantine or reject)

A company on hotmaii.com with Microsoft 365 mail and a Microsoft verification token comes back as a plain business address with no suggestion.

Where it fits in a check

The list check runs first. Many common typo domains, gmial.com and gnail.com among them, appear on the public disposable-domain lists isBusinessEmail imports, so they come back with category: "disposable", and the suggestion is filled in anyway. A domain on no list gets the typo check and then DNS. If the mistyped domain doesn’t exist, as with hotmail.cmo, the category is invalid and the suggestion is still there.

What the API returns

The suggested domain is in did_you_mean, and reasons includes typo_suspected. A trimmed response for jane@gmial.com:

{
  "email": "jane@gmial.com",
  "domain": "gmial.com",
  "category": "disposable",
  "recommendation": "block",
  "is_disposable": true,
  "did_you_mean": "gmail.com",
  "reasons": ["disposable_provider", "typo_suspected"]
}

And for jane@hotmail.cmo, a domain that doesn’t exist:

{
  "domain": "hotmail.cmo",
  "category": "invalid",
  "recommendation": "block",
  "did_you_mean": "hotmail.com",
  "reasons": ["typo_suspected", "invalid_domain"]
}

The flag also feeds the policy. A registered typo domain with working mail servers usually comes back unknown, or business if its DNS looks more established, and the flag keeps the business case out of a plain allow:

Typo domain comes back as b2b strict lenient
business with typo_suspected review block allow
unknown review block allow
disposable or invalid block block block

lenient ignores typos on purpose: it only blocks addresses that can’t work at all. Whatever the policy, read did_you_mean yourself, and read it before category. Otherwise jane@gmial.com gets your disposable-inbox message, which is accurate but useless: she meant Gmail. Reason codes and response fields describe both fields, and categories and policies has the full policy table.

Show it as a one-click fix

The pattern is the same on every form:

  1. Show the suggestion next to the field: “Did you mean jane@gmail.com?”, with the corrected address as a button.
  2. Never replace the input silently. The person may have typed exactly what they meant, and a silent change is hard to notice and hard to undo.
  3. Check again after they accept. On a work-email form, jane@gmail.com then gets your personal-address hint. That still beats an account nobody can reach.
  4. Show it before any error message, for the reason above.

In the browser, use a publishable key restricted to your sign-up page’s origin; its reduced response includes did_you_mean and the top reason codes:

const input = document.querySelector('#email');
const hint = document.querySelector('#email-hint'); // aria-live="polite"

// "jane@gmial.com" + "gmail.com" -> "jane@gmail.com", or null.
function suggestedAddress(email, result) {
  const codes = (result.reasons ?? []).map((r) => r.split(':')[0]);
  if (!result.did_you_mean || !codes.includes('typo_suspected')) return null;
  return `${email.slice(0, email.lastIndexOf('@'))}@${result.did_you_mean}`;
}

async function checkAndHint() {
  const email = input.value.trim();
  hint.replaceChildren();
  if (!email.includes('@')) return;
  const result = await checkEmail(email); // POST /v1/check; null on timeout or error
  if (!result) return;

  const fix = suggestedAddress(email, result);
  if (fix) {
    const button = document.createElement('button');
    button.type = 'button';
    button.textContent = fix;
    button.addEventListener('click', () => {
      input.value = fix;
      checkAndHint(); // the corrected address gets its own verdict
    });
    hint.append('Did you mean ', button, '?');
    return;
  }
  if (result.recommendation === 'block') hint.textContent = messageFor(result.category);
}

input.addEventListener('blur', checkAndHint);

checkEmail wraps the fetch from the signup form guide, which also has messageFor. The code tests for typo_suspected because did_you_mean is also filled for lookalike domains, where it names the provider being imitated. That isn’t a fix to offer with one click; lookalike and punycode domains covers how to handle those.

On the server, return the suggestion with the field error so the form can show it even if the browser hint never ran:

const verdict = await checkWorkEmail(email); // secret key, fails open
if (verdict.did_you_mean && verdict.reasons?.includes('typo_suspected')) {
  const local = email.slice(0, email.lastIndexOf('@'));
  return res.status(422).json({
    field: 'email',
    message: 'Please check your email address.',
    suggestion: `${local}@${verdict.did_you_mean}`,
  });
}

To let people insist on what they typed, accept a “suggestion declined” flag from the form and send those sign-ups to review.

What typo detection doesn’t cover

  • Company domains. Suggestions only cover popular providers, not every company domain. A typo such as acme.oi usually comes back invalid because the domain doesn’t exist or can’t receive mail. If someone registered it and it does receive mail, it looks like any other small company domain.
  • The name before the @. jnae@acme.io looks valid to any classifier. isBusinessEmail classifies domains; it never sends mail or probes mailboxes, so only your confirmation email catches these. Email verification vs email classification explains the split.
  • Two slips at once, such as gmial.con: a swap plus a changed ending is two edits with a different ending, so it gets no suggestion unless the domain is already on a list.
  • Deliberate lookalikes. gmail.com spelled with a Cyrillic а is not a slip. It’s a separate check with its own flag, is_lookalike.

Measure it

Add three counters to your sign-up analytics: suggestion shown, suggestion accepted, suggestion declined. Store the domain, not the full address. After a few weeks, compare confirmation rates and look at the declined ones by hand. If a declined suggestion turns out to be a real company’s domain, report it through the feedback endpoint; a person reviews every report before any list changes.

Next steps

  1. Wire the hint and the server check with the signup form guide.
  2. Look up typo_suspected, lookalike_domain and the rest in reason codes.
  3. Read how to require a work email at sign-up for the copy and policy around the field.
  4. Get a free API key and try jane@gmial.com against your own form.

Frequently asked questions

What does gmial.com mean in an email address?

Almost always a typo of gmail.com: the i and the a were swapped while typing. Mail sent to jane@gmial.com either bounces or reaches whoever controls the gmial.com domain, never the person who meant jane@gmail.com.

How does email typo detection work?

It compares the domain after the @ with a list of popular email providers and counts the single-character edits between them. One edit, such as a swapped, missing, extra or wrong letter, is a likely typo. Common ending slips such as .con for .com are fixed with a small lookup table.

Should I automatically correct email typos?

No. Show the suggestion next to the field and let the person accept it with one click. They may have typed exactly what they meant, and a silent change to an address is hard to notice and hard to undo.

Does isBusinessEmail catch typos in company domains?

No. Suggestions only cover popular email providers such as gmail.com, outlook.com and yahoo.com. A typo in a company domain usually comes back invalid because the mistyped domain doesn't exist or can't receive mail, and a typo in the name before the @ is only caught by a confirmation email.

Will a real company on a domain like a provider's be flagged as a typo?

Not when its DNS shows strong evidence of an organization: Google Workspace or Microsoft 365 mail, an email security gateway, SaaS verification tokens, a Microsoft Entra tenant, or business senders in SPF with an enforcing DMARC policy. That evidence clears the typo flag.

What is the difference between a typo domain and a lookalike domain?

A typo domain is a slip of the keyboard, such as gmial.com. A lookalike domain is built to look identical to a real one, for example gmail.com spelled with a Cyrillic letter, and usually signals impersonation rather than a mistake.