Look-alikes · typo-squats and homoglyphs

Every name that could pass for yours.
Then which are taken.

Give it a brand’s own domain. It makes every look-alike sixteen methods can reach — the slipped key, the doubled letter, the Cyrillic а that prints exactly like a Latin a — asks DNS which of them exist, and asks the registry of each one that does who holds it and since when.

DC‑L1 Look-alike scanner

16 methods · up to 600 names

A brand’s own domain — any ending. Internationalised names work: bücher.de.

Include
Owners
Try

What a scan does

Up to six hundred look-alikes, made by the sixteen methods below and shared fairly between them, so a long name’s hundreds of typing slips cannot crowd out its three homoglyphs. Each is checked for a delegation in DNS, a web address and mail; the registered ones are put to their own registry for the registrar and the date. The look-alikes are listed, never linked.

L1

The sixteen methods

How a look-alike is made

A name only has to look right for a second.

Nobody reads an address letter by letter. They read its shape, and a look-alike is anything with the same shape — close enough on a phone, in a hurry, in the preview line of an email. Here is how they are made, what this page can and cannot find out about them, and what to do about one.

01Sixteen ways to imitate a name

Most look-alikes are typing mistakes waiting for someone to make them, and the rest are made to be misread. The scanner runs each method over the name’s own label — the part before the ending — and keeps the ending, except for the last method, which keeps the label and changes the ending. Every candidate is turned into exactly the name a registry would hold, and anything a registry could not hold is dropped.

MethodFrom paypal.comWhy it works
Whole-script homoglyphраураӏ.comEvery letter Cyrillic; one script, so the mixed-script alarms stay quiet.
Homoglyphраypal.comA Cyrillic р where the p was. Identical in most typefaces.
ASCII look-alikepaypa1.comA one for an l, rn for m, vv for w.
Accents & Latin variantspáypal.comAn accent that disappears at small sizes.
Brand wordspaypal-login.comReads like a page the brand would run.
Omissionpaypl.comOne key missed.
Transpositionpapyal.comTwo keys in the wrong order.
Adjacent keypaypak.comThe key next door.
Repetitionpaypall.comOne key pressed twice.
Vowel swappaypel.comThe vowel people are unsure of.
Hyphenationpay-pal.comLooks like the brand spelled out.
Dot insertionpay.pal.comA subdomain of pal.com, run by whoever holds that.
Insertionpaypalo.comA neighbouring key caught as well.
Additionpaypals.comOne more character on the end.
Bit flippaypam.comOne bit changed in memory: l is 0x6C, m is 0x6D.
Other endingspaypal.cmCameroon’s ending, one letter short of .com.

Shorter names have fewer look-alikes and longer names have many more — a fifteen-letter name makes several hundred adjacent-key and insertion variants on its own. So the list is capped at six hundred and filled one method at a time in turn, heaviest first: the cap trims the long tail of typing slips, never the handful of homoglyphs. A name several methods reach is kept once and lists them all.

02Homoglyphs, punycode and what a browser shows

Since 2003 a domain name can be written in almost any script. Underneath, the DNS still only carries letters, digits and hyphens, so an internationalised label is stored in an ASCII encoding called punycode (RFC 3492), marked by xn--: bücher.de is held as xn--bcher-kva.de. The encoding is exact and reversible, which is the problem: the Cyrillic аррӏе.com — every letter of it Cyrillic — is a different name from apple.com, held as xn--80ak6aa92e.com, and prints identically.

The homoglyphs used here are only pairs that Unicode’s own confusables list (the security data file published with Unicode Technical Standard #39) records as confusable with a Latin letter: Cyrillic а, е, о, р, с, у, х, і, ј, ѕ, һ, ԁ, ԛ, ԝ and ӏ, and Greek ο, α, ρ, ι, ν, υ and γ among them. Each homoglyph in the results is shown character by character with its code point and script, because the whole point of one is that the eye cannot tell.

Two things blunt the trick, and neither is complete. Most registries refuse a label that mixes scripts, so раypal.com — one Cyrillic letter among Latin ones — is usually unregistrable; the whole-script version is not. And browsers show a suspicious name as its xn-- form in the address bar — Chrome for mixed scripts and for whole-script look-alikes of Latin names under Latin endings, Firefox for mixed scripts. But the address bar is not where a look-alike does its work: a link in an email, a chat message, a QR code or a printed page shows whatever text its author chose.

03What “registered” means on this page

The first pass asks one public resolver a single question about each look-alike: does its ending’s zone delegate it to nameservers? A name with nameservers is Registered — somebody holds it and pointed it somewhere. For those, it also asks whether the name has a web address (an A record) and whether it takes mail (MX records), because a look-alike that can send and receive email is the one a phishing message comes from.

A name the resolver says does not exist is only Probably unregistered, in amber. A registered name can sit with no nameservers at all — bought and parked, or held back by the registry — and from DNS it looks exactly like nobody’s. Each row can be put to its registry with Ask the registry, which turns “probably” into what the registry itself says. A question that fails is Unknown. And some endings answer every name, registered or not; a look-alike that answers without nameservers of its own is marked as that, not as taken.

04Whose are they?

Often the brand’s own. Large companies register their commonest misspellings and endings defensively, usually through a brand-protection registrar — MarkMonitor, CSC, Com Laude, Safenames — and point them at the real site. So before ranking anything, the scan reads the original’s record too, and a look-alike held at the same brand-protection registrar, or with its DNS run by the same provider, is marked and ordered lower. That is a likelihood, not a finding: a record this page cannot see behind redaction may say otherwise.

What pushes a look-alike up the order is what makes it useful to somebody else: a letter swap you cannot see, mail servers ready to send, a web address answering, and a registration made in the last ninety days. The rule is printed with the results, number by number.

05What to do about one

  1. Open its WHOIS — every row links to it. The registrar’s abuse address is in the Registrar panel; a report there, with the look-alike and what it does, is the fastest route when it is actively phishing.
  2. Watch its certificates. A look-alike about to be used almost always gets a certificate first, and every certificate is public — the Certificates page reads the logs for any name.
  3. For a trademark, the Uniform Domain-Name Dispute-Resolution Policy (UDRP) and, for the new generic endings, the faster Uniform Rapid Suspension (URS) can take a name from a holder who registered it in bad faith. Country-code endings run their own dispute schemes.
  4. Register the worst few yourself. The high-ordered, unregistered ones — a whole-script homoglyph, the .cm and .co twins — cost less to hold than to recover.
  5. Publish DMARC at p=reject on your own name. It stops mail forged as your domain; it does nothing for mail from a look-alike, which is why the Mail lamp matters here.

06How this scan works

  1. Your input is read the way the WHOIS engine reads it: scheme, path and login stripped, an internationalised name converted under UTS #46, the registrable domain found from the public suffix list.
  2. The sixteen methods run in this browser. Each candidate is encoded to its A-label with RFC 3492, and the browser’s own URL parser must agree byte for byte, or the candidate is dropped.
  3. The names go to this site’s server in batches of up to 120, and it asks Google’s public resolver (Cloudflare’s as the fallback) over plain DNS for each one’s NS, A and MX. Answers are cached for an hour. If the server cannot answer, this browser asks Google’s DNS-over-HTTPS service directly and says so above the table.
  4. Each registered look-alike is put to its own registry through the WHOIS engine’s quick lookup — RDAP where the ending has it — paced to about thirty-eight a minute.
  5. Nothing is fetched from any look-alike itself. No page is opened, no link is followed.

What it will never claim

Four answers this page refuses to give.

01

Unregistered is not free.

A look-alike with no delegation is Probably unregistered — amber, never green — and even the registry’s own “no record” means only Not registered: registries hold names back, and a registrar’s search has the last word.

02

A look-alike is not an accusation.

A registered look-alike may belong to the brand, to a business with the same letters for its own reasons, or to nobody doing anything. This page reports what DNS and the registry say, and orders by a printed rule.

03

It will not visit them.

No look-alike is opened, fetched or linked. They are named, so they can be looked into with care — not handed to a reader one click from a phishing page.

04

A failure is not a result.

A DNS question that times out, a registry that does not answer: each is Unknown, counted and shown, never folded into the good news.