What Is a Lookalike Domain?
A lookalike domain is registered or constructed to resemble a name people already trust. The goal is often to make a fake login, invoice, or support message feel familiar at a glance.
Common lookalike techniques
Attackers may swap characters, such as 0 for o or 1 for l; use combinations such as rn to resemble m; add words such as secure, billing, login, or support; or place a trusted name in a misleading subdomain. Typosquatting uses common typing mistakes or omitted characters to register a domain that looks close to the intended address.
Character substitution can also use visually similar letters from another alphabet. For example, company.example.attacker.test belongs under attacker.test—not company.example.
Read the destination carefully
Find the hostname after https:// and before the next slash. Ignore branding elsewhere in the path or query. Text before an @ symbol is user information and can be used as a distraction.
Lookalike does not always mean malicious
Different organizations can have legitimately similar names, and companies may use service-specific domains. Local structure analysis cannot confirm ownership, so treat resemblance as a reason to verify rather than proof of fraud.
Safer verification
Check the registrable domain—the meaningful name immediately before the final domain ending—and do not rely on a logo, page design, HTTPS, or words in a subdomain. Use the organization's known app, a saved bookmark, or a phone number from a trusted source. Avoid using contact details supplied by the questionable message or page.
When a destination is unexpected, use the Web MultiTools Link Checker for a local structural review, but remember that structure alone cannot prove ownership or safety.
Check a suspicious link
Paste the URL into the local Link Checker to inspect its structure without visiting the website.
Check a Link