How to spot a lookalike domain
A lookalike domain is a web address built to imitate a trusted brand using small spelling changes, extra words, or swapped characters, so a fake site can pass for the real one.
Why lookalike domains work
People do not read web addresses letter by letter. We glance at them and match the shape to a brand we know. Scammers rely on that. They register an address that looks close enough to a real one, put a copied login page on it, and wait for someone to sign in. The whole scam rests on a moment of fast reading.
The address is the one part of a page that is hard to fake. Anyone can copy a logo, a layout, and the colors of a bank or a shop. Nobody else can own the real address. So the address bar is your most reliable check, as long as you know where to look.
The one part that matters most
A web address has a main part that names the real owner of the site. It is the word right before the ending, such as .com, .net, or .org. In login.paypal.com, the owner is paypal. In paypal.secure-login.com, the owner is secure-login, and paypal is just a word placed early to fool you.
Read from the ending backward. Find the ending, then read the word just before it. That word, plus the ending, is who really controls the page. Everything to the left of it can be anything the attacker wants, including a brand name dropped in to catch your eye.
Common tricks to watch for
- Misspellings. A single changed, added, or missing letter, such as paypa1.com, netfliix.com, or amazonn.com. At a glance these read as the real name.
- Swapped characters. A zero for the letter o, or the number one for a lowercase L, as in g00gle.com or paypa1.com. On many screens they look almost identical.
- Lookalike letters from other alphabets. Some characters from other writing systems look like ordinary letters but are different underneath. The name reads as "apple" but is not the real address at all. This trick is called a homoglyph.
- The brand as a subdomain. An address like microsoft.login-verify.com puts the trusted name early, where you notice it, while the real owner is login-verify.
- Extra words that sound official. Words like secure, verify, support, billing, or account bolted onto a brand name, such as apple-support-billing.com. Real companies rarely need to string these together.
- Unusual endings. A famous brand on an ending you would not expect, sometimes chosen because it is cheap to register and often abused.
How to protect yourself
You do not have to become an expert. A few habits catch most lookalike domains.
- Before you type a password, read the address from the ending backward and check the owner name.
- Reach important sites yourself. Type the address you know or use a saved bookmark instead of clicking a link in an email or message.
- Let a password manager help. It fills your login only on the exact address it saved. If it stays empty on a page that looks familiar, treat that silence as a warning.
- Slow down when a message pushes urgency. Fake addresses do their best work when you are rushed.
- Be extra careful with pages that ask for a password, a card number, or a recovery phrase.
Fish Catcher does this reading for you and never blocks the page. It checks the address for lookalike and misspelled brand names, for lookalike characters from other alphabets, and for tricks like a brand buried in a long subdomain chain or a raw address with no real name. When it finds a problem, it shows a plain warning and a risk color, from green for no suspicious signs up to red for strong signs of a fake. You still decide what to do, with the reason spelled out in front of you.
Common questions
Is a longer web address always more dangerous?
Not always, but length is often used to hide the real owner. A long address gives room to place a trusted brand name early, where you will see it, while the true owner sits quietly before the ending. Always find the ending and read the word just before it, no matter how long the address is.
Does the padlock icon mean a site is safe?
No. The padlock only means the connection is encrypted, not that the site is honest. Scammers can get a padlock for a lookalike address just as easily as anyone else. A padlock on paypa1.com does not make it the real PayPal.
What if the address looks correct but something still feels wrong?
Trust that feeling and stop. Do not sign in. Open a new tab and reach the site the way you normally would, by typing the address or using your bookmark. If both pages match and behave the same, you are fine. If they differ, you likely caught a fake.