Can You Spot a Fake Domain? How Homograph Attacks Work

Can you spot a fake domain?
Probably not - and that’s why you should always be careful.
At first glance, both domains appear to be claude.com. However, in the second domain, some of the letters (c, a, and e) are not Latin characters - they are visually similar Cyrillic letters.
This is known as a homograph attack. Attackers use characters from other writing systems that look almost identical to Latin letters to create fake websites designed to steal passwords, login credentials, and API keys. Don’t rely on appearance alone.
How to protect yourself
- Check the address bar: Chrome, Edge, Safari, and other modern browsers often display suspicious internationalised domains in Punycode, which typically starts with xn--.
- Use a password manager: Password managers recognise the real domain. If your saved credentials are not offered automatically, stop and verify that you’re on the correct website.
- Use passkeys whenever possible: Passkeys are bound to the legitimate domain and won’t work on a fake lookalike website.
Be especially cautious if you receive an email or message containing a link, avoid clicking it immediately. Instead, type the website address manually or use a trusted bookmark. A single nearly invisible character can take you to a completely different website.
Can you spot the difference?
- claude.com
The real Claude. - claudе.com (contains a Cyrillic “е”)
Steals your login credentials and API keys.
Note: The second line only demonstrates what a homograph attack looks like. The specific example domain may or may not exist, but the attack technique itself is real.