
The Homoglyph Attack: When a Web Address Looks Right but Isn't

Team Innvikta
Published: 10 Sep 2026 • 04 Mins read
A Domain That Looks Correct but Isn't
The web address in your browser bar can look completely correct and still take you somewhere else entirely.
A homoglyph attack works by swapping one or more letters in a domain, email address, or filename for a character from a different script that looks almost identical. A Cyrillic "a" next to a Latin "n" can produce a domain that your eyes read as real, even though it's a different string pointing to a different server.
Key Takeaways
- Homoglyph attacks swap letters for visually identical characters from another script.
- A fake domain can still receive a valid TLS certificate, so HTTPS alone proves nothing.
- Delivery channels range from email and SMS to QR codes and search ads.
- Small screens make it especially hard to spot subtle character substitutions.
- Bookmarks and direct typing are more reliable than clicking a link in a message.
- A password manager that won't autofill on a mismatched domain is a practical safety net.
How It Works
- An attacker registers a lookalike domain using visually similar characters.
- The domain receives a valid TLS certificate, so the browser may still show HTTPS.
- A phishing email, SMS, advertisement, or QR code directs the victim to it.
- The fake website mirrors the legitimate login or payment page.
- Credentials, card details, or personal information are captured by the attacker.
Why the Padlock Icon Isn't Proof of Safety
Certificate authorities issue TLS certificates based on domain ownership, not identity verification of intent. Anyone who registers a homoglyph domain can obtain a valid certificate for it just as easily as a legitimate business can for theirs. The padlock confirms the connection is encrypted - it says nothing about who actually controls the site on the other end.
This is a persistent misconception even among relatively security-conscious users: "HTTPS means safe" was true enough years ago when certificates required more scrutiny to obtain, but automated, free certificate issuance has made that assumption obsolete.
The Role of Unicode in Domain Names
Internationalized Domain Names (IDNs) allow non-Latin scripts in web addresses, which is genuinely useful for a global internet - but it also opens the door to homoglyph abuse. A domain registered using Cyrillic, Greek, or other script characters that visually resemble Latin letters can be registered and pointed anywhere, and most browsers will render it in a way that's difficult to distinguish from the legitimate original at normal reading speed.
Common Delivery Channels
Email, SMS/smishing, payment fraud, search advertising, QR-code phishing, messaging platforms, and file downloads are all used to steer victims toward homoglyph domains.
Why Mobile Devices Are Especially Exposed
Small screens compress URLs, truncate them, or hide the full address bar entirely depending on the browser and app. A subtle character substitution that might be noticeable on a wide desktop screen becomes nearly invisible on a phone, which is precisely why homoglyph attacks are increasingly paired with SMS and QR-code delivery rather than desktop email alone.
See Innvikta InSAT in Action
Explore how our interactive games, realistic phishing simulations, and gamified training modules dramatically reduce organizational human cyber risk.
Red Flags to Watch For
- Unexpected requests to log in or re-enter payment details
- Familiar-looking domains reached through emails, texts, or ads
- Subtle URL differences, especially on mobile screens
- Treating the padlock icon as proof that a site is legitimate
- Urgent messages that push you to click a link
How to Stay Safe
- Type known websites directly into the address bar or use a saved bookmark instead of clicking links in messages
- Copy a suspicious URL and paste it somewhere you can zoom in and inspect each character
- Check the address bar for the Punycode version of a domain if your browser supports revealing it
- Use a password manager, since it won't autofill credentials on a domain that doesn't exactly match the saved one
- Verify unexpected payment or login requests by going to the official app or site directly, not through the link provided
Organizational Controls That Help
Beyond individual vigilance, organizations can reduce homoglyph risk through:
- Defensive domain registration of common homoglyph variants of their own brand
- DNS monitoring services that flag newly registered lookalike domains
- Browser policies that warn on IDN domains mixing scripts within a single label
- Regular employee testing against realistic homoglyph phishing scenarios, not just generic phishing templates
Where This Fits Into a Broader Defense
Homoglyph domains are effective precisely because they exploit a split-second visual judgment call - exactly the kind of decision that structured phishing simulations and ongoing security awareness training are designed to sharpen. Innvikta's free Domain Security Analyzer is also a useful first check when a URL looks slightly off but you can't quite say why.
How Innvikta Helps
Free Domain Security Analyzer
A quick, no-cost way to check a suspicious domain before entering any credentials or payment details.
Realistic Simulation Scenarios
Innvikta's phishing simulations include lookalike-domain scenarios that train employees to catch subtle character substitutions, not just obviously fake senders.
Ongoing Awareness Reinforcement
Continuous microlearning keeps techniques like homoglyph spoofing visible to employees well beyond a single training session.
Frequently Asked Questions
A homoglyph attack replaces one or more letters in a domain, email address, or filename with a visually similar character from a different script, creating a lookalike that appears identical to the real thing at a glance.
Yes. Certificate authorities verify domain ownership, not intent, so an attacker-registered homoglyph domain can obtain a valid TLS certificate and display the padlock icon just like a legitimate site.
IDNs allow non-Latin script characters in web addresses, which enables legitimate global use cases but also lets attackers register domains using characters that visually resemble Latin letters.
Copying the URL and inspecting it character by character, checking your browser's Punycode display for the domain, and using a tool like Innvikta's Domain Security Analyzer can help surface a lookalike domain.
A password manager matches saved credentials to the exact domain they were created for. It will not autofill on a homoglyph lookalike domain, which is a strong practical signal that something is wrong.
Homoglyph domains are commonly delivered through email, SMS/smishing, payment fraud attempts, search advertising, QR codes, messaging platforms, and malicious file downloads.



