Etoolio

Homoglyph & Lookalike Domain Checker

Free homoglyph and lookalike domain checker. Paste a link, domain or text to expose Cyrillic or Greek letters, invisible characters and punycode (xn--) that imitate a real brand. Runs in your browser, nothing uploaded.

Paste a link, domain or any text to reveal characters that imitate ordinary letters, a Cyrillic a inside a Latin word, invisible characters, or a punycode (xn--) domain that displays as a real brand. This is how fake sites and senders slip past your eyes. Everything runs in your browser; nothing is sent anywhere.

Try:

The fake link your eyes cannot catch

One of the most effective phishing tricks needs no misspelling at all. An attacker registers a domain that swaps a single letter for a lookalike from another alphabet, a Cyrillic о for a Latin o, and the result is visually identical to the real site. You read the address, it looks perfect, and you sign in on a page that is not who it claims to be. This free checker exposes that trick: paste a link, domain or any text and it reveals the imposter characters, invisible characters and punycode disguises, then shows you what the string really reads as. It all runs in your browser.

How it works

  • Paste anything: a URL, a bare domain, or a suspicious name or handle.
  • See the disguise removed: lookalike letters are mapped back to the Latin letters they imitate, so you see the true skeleton.
  • Get a per-character breakdown: every suspicious character, its Unicode code point, its script, and the letter it is pretending to be.

What it catches

Three families of deception. First, homoglyphs: Cyrillic, Greek, Armenian and fullwidth characters that imitate Latin letters, and the mixed-script tokens that give them away, since real words never blend alphabets. Second, invisible characters: zero-width spaces and joiners hidden inside a name to slip past filters or split a word your eyes read as whole. Third, punycode: internationalised domains that begin with xn-- behind the scenes but display as a trusted brand, which the tool decodes so you can see the real characters. When the cleaned-up version matches a known brand, it warns you which one is being impersonated.

Why this beats guessing

Character spoofing is designed specifically to defeat the human eye, so a tool that inspects each code point is exactly the right instrument. A general chatbot is a poor fit here: pasting suspicious links into it is risky, it cannot reliably enumerate Unicode scripts or decode punycode by hand, and it will happily give a confident answer that is wrong. This checker uses a deterministic character database, so the result is exact and repeatable, and nothing you paste ever leaves your device.

One signal, not the whole story

A clean result means no character-based trickery, not that a site is safe: plenty of scams use perfectly ordinary letters, and some genuine international sites use non-Latin characters honestly. Use this alongside the rest of RealCheck, checking where a link actually goes, whether an email is spoofed, whether a QR code hides a bad address, and remember the strongest habit of all: type important addresses yourself or open them from a bookmark instead of clicking. RealCheck is a set of tools for one question in the age of AI-generated fakes: is this real?

Good to know

Homoglyph & Lookalike Domain Checker, frequently asked questions

What does the homoglyph checker do?

It reveals characters that imitate ordinary letters so a link, domain or name can pretend to be something it is not. Paste anything in and it flags Cyrillic, Greek or other lookalike letters (like a Cyrillic 'a' hidden inside a Latin word), invisible zero-width characters, and punycode (xn--) domains that display in your address bar as a trusted brand. It then shows you what the text really reads as once the disguise is removed, and whether it appears to imitate a known brand.

What is a homoglyph or IDN homograph attack?

A homoglyph is a character from one alphabet that looks almost identical to a letter in another, for example the Cyrillic 'о' and the Latin 'o'. Attackers register domains that swap one or two letters for these lookalikes, so 'apple.com' becomes a different domain that is visually indistinguishable. Because browsers can display these internationalised domains (IDNs), a link can look exactly like a real site while pointing somewhere hostile. It is one of the hardest phishing tricks to catch by eye, which is exactly why a tool is useful.

What is punycode and the xn-- prefix?

Punycode is how browsers encode domains that contain non-Latin characters into plain ASCII. Such a domain starts with xn-- behind the scenes, but your address bar may render it as the pretty Unicode version, which can be a lookalike of a real brand. This tool detects an xn-- domain and decodes it so you can see the actual characters it uses, and conversely shows the xn-- form of a Unicode domain, so the disguise has nowhere to hide.

Does a clean result mean the site is safe?

No. This tool checks for one specific trick, character-based deception, so a link with no lookalike or hidden characters can still be a scam for other reasons, and a genuine international website may legitimately use non-Latin characters. Treat a clean result as one reassuring signal, not proof of safety. The most reliable habit is to type important web addresses yourself or open them from a saved bookmark rather than clicking a link you were sent.

Is what I paste kept private?

Yes. The entire check runs in your browser using a built-in character database, and nothing you paste is uploaded to a server or logged. You can safely check suspicious links and messages without sharing them.

Is it free?

Yes, free with no signup and unlimited.