Definition · DNS & Email Spoofing
What is Homoglyph Attack?
A homoglyph attack exploits characters that look alike — either within one alphabet (the digit 1 and lowercase l, rn imitating m) or across alphabets (Cyrillic а versus Latin a) — to create domains or text that are visually indistinguishable from the real thing. A user reading pаypal.com with a Cyrillic а sees nothing wrong.
IDN homograph attacks
Internationalised domain names (IDNs) allow non-ASCII characters in domains, encoded for DNS in Punycode: аpple.com with a Cyrillic а is actually xn--pple-43d.com. This enables whole-script lookalikes that no amount of careful reading will catch. Browsers mitigate the risk by displaying the raw Punycode instead of the Unicode form when a domain mixes scripts or matches other suspicion heuristics, and many registries restrict which scripts can be combined — but coverage is not complete, and email clients and chat apps are often less careful than browsers.
Homoglyphs vs typosquatting
A homoglyph attack is a specialised form of typosquatting. Ordinary typosquatting relies on the user making or missing a typing mistake; a homoglyph domain can be pixel-identical to the genuine one, so even a vigilant user inspecting a link may be deceived.
Defences
Detection looks the same as for other lookalike domains: monitoring new registrations and Certificate Transparency logs for confusable variants of your domains, then pursuing takedowns. Technical controls help too — enforced DMARC prevents attackers from spoofing your genuine domain, pushing them onto lookalikes that monitoring can catch.