Typosquatting vs. homoglyph attacks, explained
Almost every phishing campaign starts with a domain designed to look like yours. The two oldest and most effective tricks for building one are typosquatting and homoglyph attacks. They look similar from the outside but work differently — and knowing the difference is the first step to catching both before they reach your customers.
Typosquatting: exploiting the keyboard
Typosquatting bets on human error. Attackers register the domains people reach when their fingers slip:
- Missing or doubled letters —
exmaple.com,exammple.com. - Swapped adjacent keys —
examlpe.com. - Wrong ending —
example.coorexample.cmwhere the real site is.com. - Added or dropped punctuation —
exam-ple.com.
Each variant quietly collects traffic from mistyped keystrokes. Some redirect to phishing; others sit on the brand until it is worth weaponising.
Homoglyph attacks: exploiting the eye
Homoglyph (or IDN homograph) attacks are sneakier. Instead of a misspelling, they swap a character for one that looks identical but has a different underlying code point:
- A Latin a replaced with a Cyrillic а — visually identical, technically a different domain.
- A lowercase l that reads as a capital I, or vice versa.
- A digit 0 standing in for a capital O.
Because the result can look pixel-perfect in an address bar, homoglyph domains defeat the "just look carefully" advice entirely. Many browsers now display suspicious internationalised domains in punycode (the xn-- form) as a defence, but not everywhere, and not always.
The common thread: both tricks are designed to pass a half-second glance. Detection cannot rely on people noticing — it has to be systematic.
And the one that fools everyone: combosquatting
Worth naming alongside these two is combosquatting, where your brand is spelled perfectly but wrapped in trustworthy-sounding words: brand-login, secure-brand, brand-support.net. Because the brand itself is correct, even careful readers are reassured — which is exactly why it is so common in phishing emails and fake login pages.
Catching all three early
You do not have to wait for a lookalike to attack. Several signals surface them early, often before any content exists:
- New-registration feeds — scan newly registered domains for names a short edit-distance from your brand.
- Certificate Transparency logs — every new TLS certificate is logged publicly, revealing lookalikes just before they go live.
- Homoglyph matching — compare by visual similarity, not just spelling, to catch character swaps.
- Keyword permutations — generate the plausible combosquatting patterns around your brand and watch for any to be registered.
Phish Plug watches new registrations and Certificate Transparency logs for typo, homoglyph and combo variants of your brand — then, the moment one serves a clone, crawls it as a bot and a real phone to prove any cloaking and build the takedown case.
The takeaway
Typosquatting exploits the keyboard, homoglyph attacks exploit the eye, and combosquatting exploits trust. All three are deliberately easy to overlook, which is why systematic, algorithmic detection beats human vigilance every time. Catch the domain before the trap is set, and you remove the clone before it ever reaches your customers.
Keep reading
Related articles
The phishing takedown process: abuse channels, step by step
Registrars, hosts, CDNs and safe-browsing desks — where to file, what evidence each one wants, and why routing beats blasting.
Read article Threats · 8 minWhat is credential harvesting? How phishing steals logins
Credential harvesting is the engine behind most phishing. How fake login pages capture passwords, where the data goes, and how to shut the pipeline down.
Read article Detection · 7 minHow to detect lookalike domains before they go live
Typosquatting, homoglyphs and combosquatting — the signals that expose impersonation domains early, from registration to first crawl.
Read articlePut detection and takedowns on autopilot
Run a free clone check on one domain — Phish Plug proves the cloaking and builds the case for you.