Homoglyph Attacks: How Lookalike Letters Fake Your Brand
A homoglyph attack uses characters that look like familiar letters but are technically different. In some typefaces, the resulting web address can be very difficult to distinguish from the real one. This guide explains, in plain English, how the trick works and what a business can do about it.
What a Homoglyph Attack Is
A homoglyph is a character that looks the same as, or very similar to, another. Different writing systems contain characters that can resemble Latin letters on screen. Cyrillic, for example, has a lower-case "а" that can look like the Latin "a" in many typefaces. To a computer they are different characters.
A homoglyph attack takes advantage of this by registering a web address that swaps one or more of your letters for these lookalikes. The result reads as your brand name, letter for letter, yet it is a different address that someone else controls. It is the most deceptive form of the copycat addresses we describe in our guide to lookalike domains.
How These Domains Work in a Browser
Domain names were originally limited to a small Latin character set. Internationalised domain names now allow people to use many other scripts. Behind the scenes, a browser can represent those names in an encoded form beginning "xn--", often called Punycode. That encoding is normal and supports legitimate multilingual websites; it is not evidence of a scam by itself.
The risk appears when someone chooses permitted characters specifically because they resemble a trusted brand. A browser may show the readable internationalised name or the encoded form depending on its safety rules and the mix of scripts. An email, advert or shortened display can also hide the full destination. That is why the relevant question is not simply "does this contain xn--?" but "who controls this domain, and what is it doing?"
Why It Is So Hard to Spot
With an ordinary misspelling, a careful reader may notice that a letter is wrong. With a homoglyph, the substituted character may look the same in the font being used, so visual checking alone is not dependable.
Browsers reduce this risk by showing some internationalised domain names in their encoded "xn--" form or by warning about suspected lookalikes. Those protections vary by browser, script combination and context, so checking the whole domain and treating unexpected links cautiously still matters.
How Homoglyph Fakes Are Used Against You
Once a fraudster controls a homoglyph version of your address, they can use it much like any other fake. They may build a copy of your website to steal login details or take fraudulent orders, or use the domain in deceptive messages and fake invoices. Because the address can look convincing in some fonts and contexts, checking the visible link alone may not be enough.
Why You Cannot Rely on Spotting These by Eye
Manual checking alone is weak against homoglyphs. People cannot reliably see every substitution, and there may be too many plausible variations to register defensively.
Two useful layers are character normalisation, which maps known lookalikes to a comparable form, and monitoring across certificate, registration and DNS signals. Neither replaces careful staff processes, but together they cover variations that are difficult to police by eye.
How Impostor Watch Catches Homoglyph Fakes
Impostor Watch normalises known lookalike characters and checks generated variations against public Certificate Transparency logs, newly registered domain feeds and DNS results. That allows it to detect matches such as a Cyrillic "а" substituted for a Latin "a", even though the underlying characters differ.
When it finds a match, Impostor Watch checks for a live website, mail records and signs such as a copy of your site's small browser icon (its favicon), then explains the apparent risk in plain English. If the domain is being used for abuse, you can ask us to handle the reporting process. Automated monitoring is a useful extra layer, but no detection method can guarantee that it will find every deceptive domain.
A Practical Checklist for Your Team
Teach staff to open important services from a saved bookmark or a known address rather than from an unexpected message. On payment and sign-in requests, check the whole domain, not just the brand-like word at the start. If the address unexpectedly begins "xn--", contains unfamiliar characters or looks different when copied into plain text, stop and verify the request through a separate channel.
For payment changes, use a known telephone number to confirm the request. Report suspicious links without opening them, preserve the original message, and tell whoever manages your domain or security monitoring. These habits also help with ordinary typosquatting and brand-plus-word fakes.
Frequently Asked Questions
What does "homoglyph" actually mean?
It means a character that looks the same as, or similar to, another. Here it refers to characters from different writing systems that can resemble Latin letters and be used to build a deceptive web address.
Will my web browser warn me about a homoglyph web address?
Sometimes, but not reliably. Browsers have added protections that reveal these tricks in certain cases, yet many homoglyph fakes still display as normal text, so you cannot depend on the browser to catch them for you.
How can I protect my business if I cannot see the fakes myself?
Because the human eye cannot be relied on here, monitoring is a useful extra layer. Impostor Watch normalises known lookalike characters and alerts you when its certificate, registration or DNS checks detect a match.
Worried about fakes you cannot even see? Run a free scan with Impostor Watch to uncover lookalike-letter versions of your web address.
