Nobody is fooled by a domain they read carefully. Reading one carefully is not what anybody does with an email at nine in the morning.
A domain gets read the way a word does — as a shape, anchored on the part that carries meaning. That part is the brand. The part that decides who actually controls the name is the short label just before the final dot: no meaning of its own, and sitting exactly where the eye has already stopped looking.
Every pattern below leaves the brand untouched and changes the part nobody reads. Roughly in order of how well each one survives a second look.
1. Homoglyph substitution
Take acme.com and replace the Latin a (U+0061) with the Cyrillic small letter a
(U+0430). You now own a different domain. On a screen, in very nearly any typeface, it
is the same picture — same width, same curve, same everything a person is able to see.
Nothing is misspelled. No letter is added, dropped or moved. There is no visual check anyone can run that comes back wrong, because in every respect the eye is able to test, it is your name.
This is the IDN homograph attack, named for the internationalised domain names that make it possible. Cyrillic is the usual source — it supplies twins for a, c, e, o, p and x — and Greek supplies more.
The low-tech version needs no Unicode at all, only the fact that some Latin characters are already near-twins of one another:
| Typed | Reads as |
|---|---|
rn | m |
vv | w |
l (lowercase L) | I, 1 |
0 | O |
acrne.com is the canonical example. At body-text size in a sans-serif face it is close
to unarguable.
What stops it, and what does not
Browsers do push back. Chrome, Firefox and Safari apply confusability rules and will
show the raw punycode form — xn-- followed by an encoded string — when a label mixes
scripts in ways known to be deceptive. Most registries separately restrict which scripts
may be combined inside one label.
Three holes remain, and none of them is small:
- A label written entirely in one script passes. The rules target mixing. A name containing no Latin characters at all mixes nothing, and renders natively.
- Mail clients are inconsistent. That protection lives in the browser address bar. The sender address displayed in a mail client is not held to the same standard, and the display name beside it is not held to any standard whatsoever.
- Link text is not checked at all. The visible words in a message are characters someone typed. They need bear no relationship to where the link goes, and no confusability rule applies to them.
The dependable check is not a visual one, because visually there is nothing to find.
Copy the domain and look at what you pasted: a terminal, an editor or an address bar
will render a non-ASCII name in its xn-- form. A name that looks exactly like yours
and pastes back as xn--80ak6aa92e.com is not yours.
2. The appended word
acme-billing.com. acme-support.com. acme-login.com.
This one does not try to look like a typo. It tries to look like a department.
Companies genuinely do put billing and support on their own hostnames, so
acme-billing.com reads as ordinary corporate structure rather than as an attack. It is
the most effective pattern in email for that reason: it survives being read slowly,
because there is nothing misspelled to catch on.
The tell is a hyphen where there should be a dot. The real thing is
billing.acme.com — a subdomain, controlled by whoever owns acme.com. The fake is
acme-billing.com, a completely separate registration that anyone could buy this
morning.
3. Hyphen insertion and removal
acme-analytics.com when you are acmeanalytics.com. Or the reverse.
Hyphens are semantically invisible. Readers take in the words and discard the punctuation between them, which is why this works on people who would have caught a misspelling instantly. There is nothing to catch — every letter is correct and in the right order.
Particularly effective against companies whose name is two words, which is most of them.
4. The TLD swap
acme.co for acme.com. Also .net, .org, .io, .app, .online, .site, and
country codes that resemble common endings — .cm catches people who miss the o in
.com.
This works because reading stops at the brand. The name matched, so the check is over. It is also the cheapest pattern to run at scale: the same brand can be registered across dozens of endings by one person in an afternoon, and each one is a separate domain with separate ownership and its own certificate.
5. The doubled letter
accme.com. acmee.com.
Nobody counts letters. Word recognition works on shape and on the first and last characters, and a doubled letter in the middle disturbs neither much. It also catches genuine typing errors, so it earns traffic even when nobody is being targeted.
6. The dropped letter
acm.com. ame.com.
The same mechanism as doubling, and usually more productive, because omitting a keystroke is a more common error than repeating one. Short names suffer most — the fewer letters there are, the less a missing one changes the shape.
7. The plural flip
acmes.com. Or dropping the s from a name that has one.
English plurals are grammatically invisible. The brain normalises them on the way past,
which is why people will read acmes.com and recall having seen acme.com. Cheap,
boring, and it works.
How to read a domain in three seconds
The patterns are worth recognising, but the general skill is better than any list of them, because it works on the eighth pattern too.
Read a domain from the right.
- Find the last dot. What follows it is the TLD.
- The label immediately to its left is the registrable domain. Together, those two are the name someone owns.
- Everything to the left of that is a subdomain, and it belongs to whoever owns the name you just found. It can say anything at all.
That third step is the one that matters. Consider:
acme.com.account-verify.net
There is only one owned name in that string and it is account-verify.net. The
acme.com at the front is a subdomain — it was typed by the same person who registered
the domain, and it means nothing. It is there because it is the first thing you read and
the last thing you check.
Run the same test on login.acme.com and you get acme.com, which is the real
company. Same structure, opposite answer, and the only way to tell is to start from the
right.
What this does not fix
Recognising the patterns helps you and it helps your team. It does very little for a customer who gets one convincing email, once, on a phone, in a hurry.
It also does not tell you what has been registered against your name. Knowing that
acme-billing.com is the kind of thing someone would buy is not the same as knowing
that someone bought it on Tuesday. The gap between those two is where the damage
happens, and it is the subject of
the other post in this series.
Generating the list is easy. Take your name, apply the seven transformations above, cross the result with the endings people actually use, and you have a few thousand candidates in a text file. Checking which of them exist is one lookup each.
What is not easy is doing it again tomorrow, for every name in the list, across every registry that sells one — which is the only version that tells you on Tuesday rather than after the email goes out.