Definition · DNS & Email Spoofing

What is Homoglyph Attack?

A homoglyph attack exploits characters that look alike — either within one alphabet (the digit 1 and lowercase l, rn imitating m) or across alphabets (Cyrillic а versus Latin a) — to create domains or text that are visually indistinguishable from the real thing. A user reading pаypal.com with a Cyrillic а sees nothing wrong.

IDN homograph attacks

Internationalised domain names (IDNs) allow non-ASCII characters in domains, encoded for DNS in Punycode: аpple.com with a Cyrillic а is actually xn--pple-43d.com. This enables whole-script lookalikes that no amount of careful reading will catch. Browsers mitigate the risk by displaying the raw Punycode instead of the Unicode form when a domain mixes scripts or matches other suspicion heuristics, and many registries restrict which scripts can be combined — but coverage is not complete, and email clients and chat apps are often less careful than browsers.

Homoglyphs vs typosquatting

A homoglyph attack is a specialised form of typosquatting. Ordinary typosquatting relies on the user making or missing a typing mistake; a homoglyph domain can be pixel-identical to the genuine one, so even a vigilant user inspecting a link may be deceived.

Defences

Detection looks the same as for other lookalike domains: monitoring new registrations and Certificate Transparency logs for confusable variants of your domains, then pursuing takedowns. Technical controls help too — enforced DMARC prevents attackers from spoofing your genuine domain, pushing them onto lookalikes that monitoring can catch.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.