How to spot a lookalike domain

Updated View source
Stay safe

A lookalike domain is a web address built to imitate a trusted brand with small spelling changes, extra words, or swapped characters, so a fake site can pass for the real one.

Why lookalike domains work

People do not read web addresses letter by letter. We glance and match the shape to a brand we know. Scammers register an address that looks close enough, put a copied login page on it, and wait. Anyone can copy a logo, but nobody else can own the real address, so the address bar is your most reliable check.

The one part that matters

The owner of a site is the word right before the ending (.com, .net, .org). In login.paypal.com the owner is paypal. In paypal.secure-login.com it is secure-login, and paypal is just a word placed early to catch your eye.

Anatomy of a lookalike address https:// login.microsoft.com . evil-domain.xyz /auth looks like the brand the part that matters Read from the right: the real owner is the last two parts before the first slash.
The brand sits on the left to catch your eye. The owner is evil-domain.xyz.

Common tricks to watch for

How to protect yourself

Fish Catcher reads the address for you and warns in plain words when it finds a misspelled brand, lookalike characters, or a brand buried in a long subdomain. It never blocks the page.

Common questions

Is a longer web address always more dangerous?

Not always, but length is often used to hide the owner by putting a trusted brand early, where you will see it. Find the ending and read the word before it.

Does the padlock icon mean a site is safe?

No. It means the connection is encrypted, not that the site is honest. A padlock on paypa1.com does not make it PayPal.

What if the address looks correct but something still feels wrong?

Stop. Open a new tab and reach the site by typing the address or using your bookmark. If the two differ, you caught a fake.