Unicode contains many characters that render identically to Latin letters but carry different code points: Cyrillic а for Latin a, Greek ο for Latin o. A domain built with those substitutions is a different domain in every technical sense while being the same domain to a human reading the address bar.
The Latin-script version of the same trick needs no Unicode at all. Adjacent letterforms substitute for each other at small sizes: rn reads as m, 1 as l, 0 as O. On a phone, in a notification preview, none of this survives inspection because nobody inspects it.
Browsers mitigate the Unicode case by showing punycode when a domain mixes scripts, but the mitigation is inconsistent across clients, and it does nothing for the pure-Latin variants. It also does nothing for email, messaging apps, or anywhere the link is rendered by something other than a browser address bar.
For a defender the practical consequence is that a domain list built by eye is incomplete. Enumeration has to be generated from the character-confusion tables, not from what looks wrong in a spreadsheet.
How Fraudox handles it
Scam domain takedown