Blog/Phishing

Lookalike Domains: The One-Letter Trick

Phishers register domains that look almost identical to real ones: a swapped letter, an extra word, or a different ending. How to spot lookalike domains in emails and links.

CyberWatch AI1 October 2026 · 2 min read
A laptop open to an email sign-in page

Most people glance at a domain name and see what they expect to see. Phishers take advantage of that by registering domains that differ from the real one by a single letter, an extra word or a different ending. At a glance, they pass.

Common tricks

TrickExample (illustrative)
Swapped lettersexmaplebank[.]com
Look-alike charactersexamp1ebank[.]com (1 for l), rn for m
Extra wordsexamplebank-secure[.]com, examplebank-login[.]net
Different endingexamplebank[.]co instead of .com
Subdomain disguiseexamplebank.com.account-verify[.]info
Other alphabetsLetters from other scripts that look identical

How to spot them

  1. Find the real domain: the part just before the first single slash, read from right to left. See how to read a URL.
  2. Read it slowly, letter by letter, when money or passwords are involved.
  3. Compare with what you know: bookmarks, the app, or your past emails.
  4. Let tools help: password managers will not autofill on a lookalike, and browsers warn about known phishing sites.

Do not rely on your eyes alone. The safest habit is to go to important sites through bookmarks or apps, never through links. See typosquatting.

Unsure about a domain? Paste the link into CyberWatch AI Scan for a free check.

For more, see how to recognise phishing in our complete guide.

Frequently asked questions

What is a lookalike domain?

A web or email domain made to resemble a real one closely enough that people do not notice the difference at a glance.

Can characters from other alphabets be used?

Yes. Some letters from other alphabets look identical to Latin letters. Browsers show some of these in a coded form to help, but not always.

How can businesses protect themselves?

Monitor for lookalike registrations, register common variants of your own domain, and use email authentication so your real domain cannot be spoofed.

Sources

  1. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  2. Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
  3. Report a phishing page, Google Safe Browsing
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.