Lookalike character detector
Two addresses can look identical on screen and still be made of different characters. Paste the one you don’t trust. We take it apart, name every character in it and point at the impostors.
A letter on screen is a number underneath
Computers store text as numbers called code points. Latin small “a” is U+0061. Cyrillic small “а” is U+0430. Fonts draw the two with the same shape, so your eyes can’t tell them apart, but to the domain name system they’re as different as “a” and “z”. Unicode defines more than 150,000 characters in over 160 scripts, and plenty of them look a lot like Latin letters, or exactly like them.
For decades, domain names were limited to ASCII letters, digits and hyphens. Internationalized names came later, and the rule on the wire never changed. A name with other characters gets converted to an ASCII form starting with xn--, known as punycode. münchen.de travels as xn--mnchen-3ya.de. A name written with Cyrillic letters that look like “apple” travels as xn--80ak6aa92e.com, and it belongs to whoever registered it.
That trick is called a homograph attack. Browsers defend against it in the address bar by showing the xn-- form when a name mixes scripts. Mail programs, chat apps, PDF files and printed QR codes mostly don’t bother.
What the detector tests
It starts by finding the host name inside whatever you pasted, be it a full link, an email address or a bare domain. Then it runs these tests in your browser:
- Script of every character
- A label that mixes Latin with Cyrillic, Greek, Armenian, Cherokee, Lisu, Georgian or Coptic is marked red. So is a label written entirely in one of those scripts when every letter has a Latin twin. Latin mixed with Chinese, Japanese or Korean is normal use and isn’t flagged.
- Lookalike table
- About 180 characters known to imitate a Latin letter, a digit or a punctuation mark, plus full-width and mathematical letter forms. Dots, slashes and hyphens that aren’t the real ones are red, because they move the boundary of the domain.
- Invisible and direction characters
- Zero-width spaces and joiners, soft hyphens, and the bidirectional controls. U+202E, right-to-left override, makes
invoice[U+202E]fdp.exedisplay as “invoiceexe.pdf”. - Brand resemblance
- The name is boiled down to what a reader in a hurry sees: lookalikes mapped to Latin, accents dropped,
0read aso,1asl,rnasm,vvasw,clasd. That reduced form is compared with about 95 of the names phishing imitates most: large banks in North America and Europe, payment services, parcel carriers, tax offices, mail and streaming accounts. - Address structure
- A user part before
@in a link (https://paypal.com@example.net/goes to example.net), a brand domain used as a subdomain of another, a bare IP address.
Reading the result
The summary has four counters: scripts present, lookalike characters, invisible characters, and the brand the name resembles, if there is one. Below it, “What you see, what it is” lists the same name four ways:
- Displayed: as it appears, with suspect characters highlighted and the registrable domain in bold.
- Technical form: the punycode the browser really requests.
- Read in a hurry: the reduced form used for brand comparison.
- Domain that counts: the registrable domain, the part someone had to buy. Everything to its left is up to its owner, so
paypal.com.secure-login.netis a page onsecure-login.net.
After that, the character table gives every character with its code point and script. Red marks lookalikes and invisible characters. Yellow marks combining marks and control characters. Blue is only there for information, on an accented Latin letter or a letter from another script used by itself.
Brand resemblance comes in four strengths. Three of them are red: the same reduced spelling, a spelling one letter away (two for names of ten letters or more), and a real brand domain used as a prefix. A brand name that’s merely contained in a longer domain is yellow, since resellers and partners do that for honest reasons.
Limits of a character check
The detector judges how a name is spelled, not the site behind it. secure-account-verify.com contains no trick character and no brand, so it passes cleanly while being an obvious trap. For reputation, use the unsafe-site lookup.
The brand list is short on purpose. A regional bank or a small shop isn’t on it, so their imitations only get caught when they use foreign letters or invisible characters. Very short brand names (three or four letters) are matched only as a whole label. Otherwise we’d be flagging ordinary words that happen to contain them.
A name can also be flagged and be honest. Real companies register domains in Cyrillic or Greek for people who read those languages. What you’re checking is whether the script fits the sender and the language of the message.
Questions people ask
What does a domain starting with xn-- mean?
It’s the ASCII encoding (punycode) of a domain that contains characters outside a–z, 0–9 and the hyphen. That isn’t suspicious in itself, and xn--caf-dma.com is simply café.com. Paste it here to see the characters it decodes to.
How can I tell whether a link is fake before clicking?
Copy the link address without opening it, paste it here, and read the “Domain that counts” line. If that domain isn’t the one the organization uses on its official site, don’t open the link, whatever the rest of the address says.
Does my browser protect me from homograph domains?
Partly. Chrome, Firefox, Edge and Safari display the xn-- form in the address bar when a label mixes scripts or matches a known confusable pattern. That only helps once you’ve opened the page, and only in the address bar. Nobody checks the text of a link in an email.
Can an email address contain invisible characters?
Yes. A zero-width space or a soft hyphen can be slipped in anywhere in text. Mail servers generally reject them in the domain part, but they turn up in display names, in link text and in file names, where they help a message get past keyword filters.
Why is paypa1.com flagged when it only uses normal characters?
Because the trick is in how you read it, not in how it’s encoded. Read the digit 1 as the letter l and the name becomes “paypal”, which is on the brand list, while the domain isn’t one of PayPal’s.