O3.04.4Lookalike-domain perceptual confusiondesignresearch

Spelling and visual lookalikes can fool users during rapid domain scanning

Aliases: lookalike domain · homograph domain · typosquatting

What it is

Lookalike-domain perceptual confusion uses omitted or transposed letters, adjacent characters, added brand words, or cross-script homoglyphs so a malicious registered domain is read as the expected one during a quick scan. The risk comes from whole-word perception and attention allocation, not simply ignorance of URL syntax.

Why it happens

Reading prioritizes familiar word shapes and brand fragments over character-by-character checking. Narrow-screen truncation, low contrast, long subdomains, and a registered domain hidden before branded path text further obscure the ownership boundary. Under time pressure, seeing the expected brand ends inspection. An attacker needs sufficient resemblance, not a perfect copy, and can place a real brand domain inside a malicious subdomain or path.

Studying it

Randomize genuine domains, one-character variants, homoglyphs, branded-subdomain decoys, and unrelated controls on desktop, mobile, and assistive technology. Compare rapid action with instructed inspection, measuring expansion or gaze, identification, latency, and confidence while controlling brand familiarity. Do not treat “most users” as a fixed universal proportion; estimate confusion in the target setting.

Where it stops holding

Lookalikes are one phishing route; genuine sites and accounts can also be compromised. Coloring every unusual character creates noise, and internationalized domains serve legitimate multilingual use. Defenses should combine expectation, account history, and action risk instead of banning non-ASCII text or assigning character inspection entirely to the user.

Applying it

  • Emphasize the normalized registrable domain and visually subordinate subdomain, path, and query text so brand fragments cannot mask ownership.
  • Detect new domains near a user's high-value familiar sites and show a specific comparison before login or payment rather than a generic red warning.
  • Never truncate away the ownership-determining end on narrow screens; preserve the registered domain and provide one-action expansion.
  • Test spelling variants, Unicode homoglyphs, subdomain decoys, and post-redirect destinations on real devices.

Related

  • Same group: O3.04.2 Weak domain cues · O3.04.3 Trusted provenance indicator
  • Adjacent: O3.14 Trusted-path spoofing · O3.06 Trusted path
  • Search terms: lookalike domain · homograph attack · typosquatting usability

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/O3.04.4