Trust Lab
Check for lookalike domain variations
Compare a suspicious domain with a trusted one and review misspellings, added or removed characters, hyphens, subdomains, and encoded-domain warning signs.
This is a similarity check, not proof of phishing. It does not replace brand monitoring or manual review.
Similarity result
No obvious lookalike signal
Similarity score: 0/100
Enter two public domains or URLs to compare.
Tool guidance
How to use this tool
The comparison runs in your browser and does not store the domains.
How to use it
Enter the trusted brand or domain.
Enter the suspicious URL or domain.
Compare the base domains, subdomains, wording, and similarity signals.
Read the output as a similarity check, not a verdict.
What results mean
Similarity is not proof of phishing and legitimate domains can trigger false positives.
Subdomains can look familiar while the registrable domain belongs to someone else.
Punycode and internationalized domains can be legitimate, but confusing characters deserve closer review.
What to do next
Request brand monitoring for repeated reports.
Use Manual Report when customers or payments are involved.
Report suspicious links for manual review.
FAQ
What is a lookalike domain?
A domain designed to resemble a trusted brand, product, or official website.
Does similarity prove phishing?
No. Similarity is a signal that deserves context; it is not proof of malicious intent.
Why do attackers use subdomains?
Subdomains can make a URL look familiar while the base domain belongs to someone else.
What should businesses do?
Collect suspicious reports, publish official links, and request manual review for customer-facing risks.