Technique
Lookalike Domain
Also known as: Typosquatting, Domain Spoofing, Homograph Attack, IDN Homograph Attack, URL Spoofing, Doppelganger Domain
DELIVERY
Registering domains that visually mimic legitimate websites through typos, character substitution, or homoglyphs to deceive victims into visiting malicious sites.
Common attack flows
How it fits in a scam
This technique shows up duringDELIVERY
Before
This is often where the scam begins.
Defense
How to defend against this
How to spot it
- Carefully inspect URLs character-by-character before clicking or entering data
- Look for subtle misspellings like micorsoft.com or arnazon.com
- Check for unusual TLDs like .bond .xyz .top on supposedly official sites
- Government sites use .gov - anything else is fake
- Watch for mixed character sets where Cyrillic a looks like Latin a
- Hover over links to reveal actual destination URL
- Browser warnings about deceptive sites
Further reading