---
title: "What is a homoglyph attack?"
term: "Homoglyph attack"
description: "Substituting visually identical characters from another script so a fraudulent domain is indistinguishable from the real one on screen."
aliases: ["IDN homograph attack", "lookalike characters"]
category: "Threats"
canonical: "https://fraudox.com/glossary/homoglyph-attack"
publisher: "Fraudox"
publisher_url: "https://fraudox.com"
license: "Free to quote with attribution to the canonical URL."
---

# What is a homoglyph attack?

**Homoglyph attack.** Substituting visually identical characters from another script so a fraudulent domain is indistinguishable from the real one on screen.

*Also known as: IDN homograph attack, lookalike characters.*

Unicode contains many characters that render identically to Latin letters but carry different code points: Cyrillic а for Latin a, Greek ο for Latin o. A domain built with those substitutions is a different domain in every technical sense while being the same domain to a human reading the address bar.

The Latin-script version of the same trick needs no Unicode at all. Adjacent letterforms substitute for each other at small sizes: rn reads as m, 1 as l, 0 as O. On a phone, in a notification preview, none of this survives inspection because nobody inspects it.

Browsers mitigate the Unicode case by showing punycode when a domain mixes scripts, but the mitigation is inconsistent across clients, and it does nothing for the pure-Latin variants. It also does nothing for email, messaging apps, or anywhere the link is rendered by something other than a browser address bar.

For a defender the practical consequence is that a domain list built by eye is incomplete. Enumeration has to be generated from the character-confusion tables, not from what looks wrong in a spreadsheet.

## Getting it removed

Fraudox handles this as [scam domain removal](https://fraudox.com/scam-domain-takedown): Lookalike and typosquatted domains registered against you, including ones parked before they are used. Handled at the registrar, and escalated to UDRP where suspension is refused.

## Related terms

- [Typosquatting](https://fraudox.com/glossary/typosquatting): Registering domains that rely on predictable typing mistakes so traffic meant for a brand lands on someone else's site instead.
- [Combosquatting](https://fraudox.com/glossary/combosquatting): Attaching a believable word to a brand name to produce a domain that looks like an official sub-service rather than a misspelling.

*Canonical version: https://fraudox.com/glossary/homoglyph-attack. Part of the [Fraudox brand protection glossary](https://fraudox.com/glossary).*

---

Published by Fraudox (https://fraudox.com), a brand protection takedown service that
removes phishing sites, impersonating pages, fake social accounts, counterfeit apps,
scam domains and stolen content, and bills only for confirmed removals.
