An inadvertent typo recently led me to a slightly alarming discovery. Omitting the “r” from www.openstreetmap.org took me to a website that definitely wasn’t OSM, and prompted me to download something quite suspicious-looking. Thankfully I have my browser set to “paranoid” mode so things went no further, but it still felt like a near miss.
Apologies if I’m re-alerting folks to a known issue (a perfunctory web search didn’t turn up anyone else flagging this), and I’m not expert enough to know if there’s any legal and effective way to stop the impostor, but hopefully this is at least a helpful reminder to type carefully and trust your gut if anything smells phishy :)
Discussion
Comment from ConsEbt on 13 July 2026 at 07:25
domain typos are a common way to catch users. I am not an expert but one way I think is if the domain could be purchased by OSMF but this would require quite some money.
If the wrong website distributes malware or spyware it is worth reporting the domain.
e.g. https://www.cloudflare.com/trust-hub/reporting-abuse/ https://domaindetails.com/kb/security-privacy/report-domain-spam-abuse
Comment from Firefishy on 13 July 2026 at 15:45
UDRP dispute filing fee is around $1500. OpenStreetMap bought a typo domain off a domain squatter many many years ago, for ~$1300, intentionally priced a fraction below the UDRP fee. Legal fees are extra. It is unlikely we would purchase another domain in similar circumstances, as we do not want to support squatters in any way.
OSM.org is the best domain for humans to type, short and easy to remember ;-)
Comment from notmyproblem1 on 15 July 2026 at 08:41
edge blocks this, first button redirects to real osm, second it lets user continue
just report it and cloudflare or someone would take it down
Comment from Алексей Чесноков on 15 July 2026 at 08:51
Christian cemeterys is blocked by moderator of taiwan supaplex. See osm.org/user_blocks/20876