Typosquatting.ai
LOOK CLOSER

What Is a Lookalike Domain? Definition, Examples, Checks

Some deceptive addresses are not mistyped. They are designed to survive a careful glance. Illustrative lookalikes in this guide use the reserved .test ending, so that no real registration is named.

by Andrew Maged16 September 2026updated 23 September 202612 min read

A lookalike domain is any registered name designed to be mistaken for another, whether through spelling, characters that render alike, added words, a different ending, or a brand placed inside somebody else’s subdomain.

This guide covers the definition of a lookalike domain, how the term relates to typosquatting, the difference between spelling similarity and visual similarity, what browsers do about it, documented real examples, how to check your own brand, and what a check can and cannot establish.

What is a lookalike domain?

A lookalike domain is a registered name that resembles another closely enough to be taken for it. The resemblance can come from anywhere: a dropped or swapped letter, a character from another script that renders the same, a word such as login or support attached to a correctly spelled brand, the same brand under an ending it does not use, or the brand placed as a subdomain of a name somebody else controls. What the variants share is that they borrow recognition from a name they do not own.

The term is broader than typosquatting and it is the more useful one for a brand owner, because most of the names that matter contain no typo. A message that says an account needs attention and links to example-login.test is not relying on anyone’s fingers slipping. It is relying on a reader who checks for misspellings, finds none, and trusts the name.

A lookalike is a description of a name, not a judgement about the person who registered it. Some are the brand’s own defensive registrations. Some belong to unrelated businesses. Some are parked. Establishing which is which is the work, and it is done from public records rather than from the resemblance.

Lookalike domains vs typosquatting

Typosquatting is one kind of lookalike: a name that models a typing mistake. Lookalike is the family, typosquatting is a member of it, and the other members are the ones that produce the most candidates. The table sets the kinds side by side for example.com.

Kind of lookalikeExample for example.comTyposquatting?
Dropped or doubled letterexmple.testYes
Keyboard neighbourezample.testYes
Homograph from another scriptexаmple.com (Cyrillic a)Sometimes counted
Keyword compoundexample-login.testNo
Alternative endingexample.netNo
Subdomain trickexample.com.signin.testNo
Hosted platform nameexample.pages.devNo
The rows marked No are the majority of what a generator produces and the majority of what turns up registered. A monitoring approach that only covers typos misses them.

Spelling similarity and visual similarity are different problems

A typing mistake produces a name that is wrong in a way you could spot if you looked: exmaple.test does not spell the brand. Visual similarity produces a name that is not wrong at all at a glance, because the characters chosen render almost identically to the ones they replace.

Within a single script there are plenty of these. A zero and a lower-case letter o are close in many fonts. The pair r and n set together can read as m. A capital I, a lower-case l and the digit 1 are indistinguishable in several typefaces still widely used in mail clients.

Across scripts the problem is larger. Unicode contains characters in Cyrillic, Greek and other scripts that are visually identical to Latin ones. The Latin a is code point 0061 and the Cyrillic a is 0430; to a person they look the same, to a resolver they are different names. A domain can be spelled entirely in characters that are not the ones you expect while rendering exactly like the name you know. Unicode publishes a confusables table for precisely this reason, defining two strings as confusable when their skeletons are identical, and it is the reference that detection works from.

What browsers do about it, and where that stops

Browsers are aware of the script problem and defend against the clearest cases. The common approach is to display the Punycode form of a name, the xn-- prefixed ASCII encoding, when the mix of scripts in it looks deceptive rather than natural. Chromium applies a script-mixing check based on the Unicode restriction profiles and shows the component in Punycode if it fails, and separately shows Punycode when the skeleton of the registrable part matches one of the top domains. Firefox adds checks of its own, such as displaying as Punycode any label that mixes more than one numbering system.

The rules exist because of a demonstration. In 2017 the researcher Xudong Zheng registered a name spelled entirely in Cyrillic that displayed as apple.com in Chrome and Firefox; visually the two were indistinguishable because of the font the browsers used. He reported it on 20 January 2017 and the fix shipped in Chrome 58. Because the name used a single script throughout, the mixed-script check of the time did not catch it, which is why the whole-name skeleton check exists now.

The defence is real and narrow. It applies to what the address bar shows, not to a link in an email client, a chat application, a PDF or a slide. It reasons about script mixing and a short list of top domains, so a name that stays within one script and does not resemble a very popular site is displayed normally, and internationalised domains are used legitimately by a large part of the world, so no browser can refuse them. You cannot delegate this to the browser: by the time an address bar shows you a Punycode name, the page has already loaded.

Documented lookalike domains

The examples below are the ones that can be checked against a published investigation or a vendor’s own report. Each one is a different kind of lookalike, and none of them is a typo in the ordinary sense.

xn--80ak6aa92e.com, 2017
Xudong Zheng’s demonstration name, spelled in Cyrillic and rendered as apple.com by Chrome and Firefox until Chrome 58 changed its display rules. A whole-script homograph.
xn--80a7a.com, 2018
Two Cyrillic characters that render as ca.com, reported by Brian Krebs, who noted that the Latin a is Unicode 0061 and the Cyrillic a is 0430 and that to a human they look the same.
A dotted n under krebsonsecurity, 2018
A lookalike of Krebs’s own site that replaced the n with a lowercase n carrying a tiny dot beneath it, a character used by several dozen scripts. A single-character homograph inside an otherwise Latin name.
secure-wellsfargo.org, 2020
A keyword compound recorded by Unit 42 that targeted the bank’s customers. The brand is spelled correctly; the added word supplies the pretext.
amazon-india.online, 2020
Brand, keyword and an alternative ending together, set up according to Unit 42 to steal credentials from mobile users in India.
netflix-payments.com, 2020
Unit 42’s example of the compounds that appear in phishing emails and on scam websites to convince people they are on content the brand maintains.
Unit 42’s detector found 13,857 squatting domains registered in December 2019 alone, an average of 450 a day. The documented cases above are a handful from that stream, chosen because each was written up.

How to check for lookalike domains on your own brand

Start from the registrable form of your name, because that is what a registration covers, and generate candidates mechanically rather than by imagination. A person writing out variations produces a few dozen and stops. A generator produces every kind in the table above at once, across every common ending, and the important step is then to resolve each candidate over DNS so the result lists names that exist rather than names that could.

For the names that resolve, look at the record rather than the page. The registry’s RDAP record gives the creation date and registrar; DNS shows whether a host is reachable and whether mail is configured; certificate transparency logs show whether a certificate has been issued, which often happens days before a page appears; passive scanning services show what a host looked like when somebody else visited it. None of that requires anyone to open the site.

The checker on this site runs that process for a domain you own, without an account. It generates candidates from about twenty pattern families across roughly 180 endings, resolves them over DNS over HTTPS, and takes its evidence from registry RDAP, certificate transparency logs and passive urlscan.io search; it never connects to a suspect site. For example.com it produces 3,001 candidates and resolves the first 2,970. On the Pro plan a domain is re-checked daily and certificate logs are searched every 30 minutes. The rules behind every label are on the methodology page.

Read the domain, not the brand name in it

A brand name appearing in a link tells you nothing about who controls the destination. What matters is the registrable domain, and it is found by reading from the right.

  • In accounts.example.com the registrable domain is example.com, and the owner of example.com controls it.
  • In example.com.signin.test the registrable domain is signin.test. The familiar brand is a subdomain of somebody else’s name.
  • In example.com-login.test the registrable domain is again not example.com. A hyphen is an ordinary character in a label; the dot is what separates ownership.
  • In example.co.uk the registrable domain is the whole of example.co.uk, because co.uk is a public suffix, one under which the public can register names directly, rather than a domain somebody owns. This is why the Public Suffix List exists and why any tool that reasons about ownership needs it.

Added words create familiarity that nothing has earned

A brand followed by login, billing, support, verify or secure reads as an official subsection of a service. It is not. Those names are simply registrations, available to anybody, and they are the largest group of candidates any generator produces for any domain.

The reason they work is that they arrive with a pretext. A message says an account needs attention and offers a link where the brand is spelled correctly and the added word matches the story. Nothing in the name is misspelled, so a reader checking for typos finds none. The documented compounds above, secure-wellsfargo.org and netflix-payments.com among them, are exactly this shape.

The defence is the same as for any address: confirm the registrable domain against a source you already trust, such as a saved bookmark or a statement you were sent through a channel you initiated, rather than against the message that is asking you to act.

Different endings mean different owners

The same name under .com, .net, .co, .io or a country ending may be held by entirely different parties, and frequently is. Short names in particular collide across industries and jurisdictions without anybody acting in bad faith.

This cuts two ways when you review your own findings. A registered variation under an unfamiliar ending is not evidence of an attack, and may be an unrelated business with an equal claim to the word. Equally, a brand that owns its name under one ending has not secured anything: the endings a customer is most likely to assume are the ones worth holding.

The comparison that makes this tractable is against your own inventory. A large share of the findings on a first check are the organisation’s own defensive registrations, and a variation that shares your registrar and nameservers is far more likely to be yours than anyone else’s. Mark it as such before it consumes anyone’s attention.

The limits of a single check

A check samples patterns. Even a generator working from twenty families and nearly two hundred endings does not cover every script, every ending or every possible subdomain of every hosting platform, and it does not read the page behind any name it finds.

So an empty result means the patterns checked found nothing registered. It does not mean a brand is unimitated. And a full result is a list of names to review, in a published order, not a list of accusations. Similarity is never proof of intent; a review priority is a position in a queue, not a finding of phishing.

Common questions

What is a lookalike domain?
A lookalike domain is a registered name designed to be mistaken for another one. The resemblance can come from a misspelling, a character from another script that renders the same, a word such as login added to the brand, a different ending, or the brand placed inside somebody else’s subdomain. It describes the name, not the registrant’s intent.
Is a lookalike domain the same as typosquatting?
Typosquatting is one kind of lookalike, the kind that models a typing mistake. Lookalike is the wider term and includes keyword compounds, alternative endings, homographs and subdomain tricks, which together produce far more registered names than typos do.
What is a homograph domain?
A homograph domain uses characters that look like the expected ones but are different code points, usually from Cyrillic or Greek. In 2017 a name spelled entirely in Cyrillic displayed as apple.com in Chrome and Firefox until Chrome 58 changed its rules. Browsers now display such names as Punycode, beginning xn--, when the script mix looks deceptive.
How do I find lookalike domains of my company?
Generate candidates from your registrable domain across every family and every common ending, resolve them over DNS to keep only the ones that exist, then read the RDAP record, DNS records and certificate log entries for each. Compare the list against your own registrations first, because many first-check findings are defensive names you already own.
Are lookalike domains illegal?
Not by themselves. A lookalike becomes actionable when it is registered in bad faith to profit from someone else’s mark, which is what the UDRP and the US Anticybersquatting Consumer Protection Act address, or when it is used for fraud. An unrelated business or a defensive registration by the brand itself is a lookalike and is entirely lawful.

Sources and further reading

  1. Unicode Technical Standard #39: Unicode Security Mechanisms (confusables)
  2. RFC 5890: Internationalized Domain Names for Applications (IDNA): definitions
  3. RFC 3492: Punycode
  4. Chromium: IDN display policy
  5. Mozilla: IDN display algorithm
  6. Xudong Zheng: Phishing with Unicode domains (2017)
  7. Krebs on Security: Look-alike domains and visual confusion (2018)
  8. Unit 42: Cybersquatting: attackers mimicking domains of major brands
  9. Public Suffix List
  10. ICANN: Registration Data Access Protocol (RDAP)
  11. ICANN: Uniform Domain-Name Dispute-Resolution Policy (UDRP)
  12. Typosquatting.ai: methodology and data sources

Keep reading in Typosquatting