Detection

Typosquatting vs. homoglyph attacks, explained

Phish Plug ResearchSeptember 26, 20267 min read

Almost every phishing campaign starts with a domain designed to look like yours. The two oldest and most effective tricks for building one are typosquatting and homoglyph attacks. They look similar from the outside but work differently — and knowing the difference is the first step to catching both before they reach your customers.

Typosquatting: exploiting the keyboard

Typosquatting bets on human error. Attackers register the domains people reach when their fingers slip:

  • Missing or doubled letters — exmaple.com, exammple.com.
  • Swapped adjacent keys — examlpe.com.
  • Wrong ending — example.co or example.cm where the real site is .com.
  • Added or dropped punctuation — exam-ple.com.

Each variant quietly collects traffic from mistyped keystrokes. Some redirect to phishing; others sit on the brand until it is worth weaponising.

Homoglyph attacks: exploiting the eye

Homoglyph (or IDN homograph) attacks are sneakier. Instead of a misspelling, they swap a character for one that looks identical but has a different underlying code point:

  • A Latin a replaced with a Cyrillic а — visually identical, technically a different domain.
  • A lowercase l that reads as a capital I, or vice versa.
  • A digit 0 standing in for a capital O.

Because the result can look pixel-perfect in an address bar, homoglyph domains defeat the "just look carefully" advice entirely. Many browsers now display suspicious internationalised domains in punycode (the xn-- form) as a defence, but not everywhere, and not always.

The common thread: both tricks are designed to pass a half-second glance. Detection cannot rely on people noticing — it has to be systematic.

And the one that fools everyone: combosquatting

Worth naming alongside these two is combosquatting, where your brand is spelled perfectly but wrapped in trustworthy-sounding words: brand-login, secure-brand, brand-support.net. Because the brand itself is correct, even careful readers are reassured — which is exactly why it is so common in phishing emails and fake login pages.

Catching all three early

You do not have to wait for a lookalike to attack. Several signals surface them early, often before any content exists:

  1. New-registration feeds — scan newly registered domains for names a short edit-distance from your brand.
  2. Certificate Transparency logs — every new TLS certificate is logged publicly, revealing lookalikes just before they go live.
  3. Homoglyph matching — compare by visual similarity, not just spelling, to catch character swaps.
  4. Keyword permutations — generate the plausible combosquatting patterns around your brand and watch for any to be registered.

Phish Plug watches new registrations and Certificate Transparency logs for typo, homoglyph and combo variants of your brand — then, the moment one serves a clone, crawls it as a bot and a real phone to prove any cloaking and build the takedown case.

The takeaway

Typosquatting exploits the keyboard, homoglyph attacks exploit the eye, and combosquatting exploits trust. All three are deliberately easy to overlook, which is why systematic, algorithmic detection beats human vigilance every time. Catch the domain before the trap is set, and you remove the clone before it ever reaches your customers.

Put detection and takedowns on autopilot

Run a free clone check on one domain — Phish Plug proves the cloaking and builds the case for you.