Typosquatting and homoglyphs: how a single letter tricks your eyes

Last updated:

Frequently asked questions

What is typosquatting?

Typosquatting is a cyber attack technique where fraudsters register domain names that are slight misspellings of well-known brands (e.g. googel.com instead of google.com) or use alternate extensions to deceive users.

What is an IDN homoglyph attack?

A homoglyph attack uses visually identical characters from different alphabets (such as Cyrillic or Greek) or lookalike letters (like an uppercase “I” mimicking a lowercase “l”) to create fake domains that are virtually undetectable to the human eye.

Why can't the human eye reliably spot a homoglyph?

In standard modern system fonts, the Cyrillic “a” (U+0430) and the Latin “a” (U+0061) are rendered identically. Only automated tools that inspect the raw Punycode string can reliably detect the manipulation.

How do security tools and browsers handle lookalike domains?

While browsers display a technical “xn--” prefix for some mixed-script domains, attackers constantly adapt to bypass basic filters. Resku compares every visited domain against a database of over 60 protected brands in real time.

More guides
Protect your browser

A single invisible character swap is enough to steal your credentials. Resku inspects domain strings in ~200 ms and compares addresses against over 60 monitored brands.

Join the waitlist
← Back to all guides