Lookalike Domains: The One-Letter Trick
Phishers register domains that look almost identical to real ones: a swapped letter, an extra word, or a different ending. How to spot lookalike domains in emails and links.

Most people glance at a domain name and see what they expect to see. Phishers take advantage of that by registering domains that differ from the real one by a single letter, an extra word or a different ending. At a glance, they pass.
Common tricks
| Trick | Example (illustrative) |
|---|---|
| Swapped letters | exmaplebank[.]com |
| Look-alike characters | examp1ebank[.]com (1 for l), rn for m |
| Extra words | examplebank-secure[.]com, examplebank-login[.]net |
| Different ending | examplebank[.]co instead of .com |
| Subdomain disguise | examplebank.com.account-verify[.]info |
| Other alphabets | Letters from other scripts that look identical |
How to spot them
- Find the real domain: the part just before the first single slash, read from right to left. See how to read a URL.
- Read it slowly, letter by letter, when money or passwords are involved.
- Compare with what you know: bookmarks, the app, or your past emails.
- Let tools help: password managers will not autofill on a lookalike, and browsers warn about known phishing sites.
Do not rely on your eyes alone. The safest habit is to go to important sites through bookmarks or apps, never through links. See typosquatting.
Unsure about a domain? Paste the link into CyberWatch AI Scan for a free check.
For more, see how to recognise phishing in our complete guide.
Frequently asked questions
What is a lookalike domain?
A web or email domain made to resemble a real one closely enough that people do not notice the difference at a glance.
Can characters from other alphabets be used?
Yes. Some letters from other alphabets look identical to Latin letters. Browsers show some of these in a coded form to help, but not always.
How can businesses protect themselves?
Monitor for lookalike registrations, register common variants of your own domain, and use email authentication so your real domain cannot be spoofed.
Sources
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
- Report a phishing page, Google Safe Browsing


