Spelling and visual lookalikes can fool users during rapid domain scanning
Aliases: lookalike domain · homograph domain · typosquatting
What it is
Lookalike-domain perceptual confusion uses omitted or transposed letters, adjacent characters, added brand words, or cross-script homoglyphs so a malicious registered domain is read as the expected one during a quick scan. The risk comes from whole-word perception and attention allocation, not simply ignorance of URL syntax.
Why it happens
Reading prioritizes familiar word shapes and brand fragments over character-by-character checking. Narrow-screen truncation, low contrast, long subdomains, and a registered domain hidden before branded path text further obscure the ownership boundary. Under time pressure, seeing the expected brand ends inspection. An attacker needs sufficient resemblance, not a perfect copy, and can place a real brand domain inside a malicious subdomain or path.
Studying it
Randomize genuine domains, one-character variants, homoglyphs, branded-subdomain decoys, and unrelated controls on desktop, mobile, and assistive technology. Compare rapid action with instructed inspection, measuring expansion or gaze, identification, latency, and confidence while controlling brand familiarity. Do not treat “most users” as a fixed universal proportion; estimate confusion in the target setting.
Where it stops holding
Lookalikes are one phishing route; genuine sites and accounts can also be compromised. Coloring every unusual character creates noise, and internationalized domains serve legitimate multilingual use. Defenses should combine expectation, account history, and action risk instead of banning non-ASCII text or assigning character inspection entirely to the user.
Applying it
- Emphasize the normalized registrable domain and visually subordinate subdomain, path, and query text so brand fragments cannot mask ownership.
- Detect new domains near a user's high-value familiar sites and show a specific comparison before login or payment rather than a generic red warning.
- Never truncate away the ownership-determining end on narrow screens; preserve the registered domain and provide one-action expansion.
- Test spelling variants, Unicode homoglyphs, subdomain decoys, and post-redirect destinations on real devices.
Related
Cards in the same group
- O3.04.1Users have difficulty verifying source authenticity
- O3.04.2Domains and sender fields are weak cues
- O3.04.3The system should provide a trustworthy source indicator
- O3.04.5Vigilance gained from security education decays with time and fatigue
- O3.04.6Relying only on users to detect phishing is a limited defense
- O3.04.7An isolated, context-free warning does not connect users to the risk