Unicode Lookalike Characters in Emails Flagged as Phishing in 2026
Detect and remove Unicode lookalike characters in emails that mimic legitimate addresses. Prevent phishing attempts and improve inbox placement with.
Why Are Unicode Lookalike Characters a Security Risk in Email?
You’ve seen it before: an email from “[email protected]” that feels off. The domain looks right, but something’s wrong. Maybe it’s the subtle difference in the 'a' — a Cyrillic one, not Latin. That’s not a typo. It’s a homoglyph.
Unicode lookalike characters, also known as homoglyphs, exploit how humans read by using technically distinct code points that appear identical. Attackers use them to craft domains like 'paypa1.com' or 'm1crosoft.com'. These look real — even in common fonts. But they’re not.
Email clients rely on DNS lookups, which only check ASCII domain names. A Cyrillic 'а' (U+0430) doesn’t appear in standard DNS records, so the system accepts it as valid. No alert, no flag. Just a forgery that slips through the cracks.
Key takeaways
- Unicode lookalike characters mimic real letters using distinct code points, enabling domain spoofing that’s visually undetectable in many fonts.
- Email systems often fail to flag these attacks because DNS validation operates on ASCII, not visual similarity or Unicode code point differences.
- Even if your email filter blocks common phishing patterns, homoglyphs bypass it by appearing legitimate in both appearance and technical validation.
How Do Homoglyph Email Spam and Phishing Attacks Work?
Attackers use Unicode lookalike characters—like replacing the letter 'l' with the digit '1' or 'O' with '0'—to create domains that visually mimic trusted brands, such as 'examp1e.com' instead of 'example.com'. These domains resolve to real DNS records, bypassing basic validation checks, but appear suspicious only when examined closely. When sent from such a domain, phishing messages land in inboxes, tricking users into revealing login details or downloading malware.
Why Homoglyph Domains Bypass Standard Checks
Many email systems scan only for known bad domains or basic syntax errors, not visual similarity. A domain like 'paypa1.com' (with a '1' instead of 'l') is technically valid and has working DNS records, so it passes most automated filters. The subtle visual differences are hard to catch without manual review or specialized tools.
The risk is heightened because these domains often use internationally supported scripts (like Cyrillic or Arabic characters) that look identical to Latin letters at a glance. For example, the Cyrillic 'а' (U+0430) looks indistinguishable from the Latin 'a' (U+0061), enabling attacks like 'paypaл.com' — a tactic documented by researchers at the IETF as part of character-set homoglyph vulnerabilities.
How These Attacks Fool Users and Evade Detection
Once a homoglyph domain is registered, attackers can set up a full phishing infrastructure: spoofed login pages, realistic email templates, and automated campaigns. The emails appear to come from reputable sources—like your bank or a cloud service—because the domain name is nearly identical to the real one.
Even if spam filters catch some messages, a small subset slips through, especially in targeted campaigns or low-volume sends. This makes detection difficult without proactive measures. Many legacy verification tools only check syntax and basic DNS records, missing the visual deception entirely.
To catch these risks, you need verification that checks not just if a domain exists, but also whether it's visually deceptive. MailTester’s email checker analyzes domains for homoglyph risks and flags suspicious character substitutions before you send. By testing your list with our bulk verification tool, you can uncover risky addresses that look real but aren’t.
Common Examples of Homoglyph Phishing Domains You Should Know
Phishing domains often use Unicode lookalike characters to mimic legitimate websites—like replacing 'g' with Cyrillic 'г', or 'o' with digit '0'. These homoglyphs trick users into thinking they're visiting a real site. Let's break down the most common ones you should be tracking in your email and domain checks.
Real-World Homoglyph Attacks to Watch For
- Using 'г' (Cyrillic small letter g) instead of 'g' in
amazоn.com—look closely; that 'о' is actually a Cyrillic 'о', not the Latin 'o'. A subtle change, but enough to bypass basic scrutiny. - Replacing 'o' with '0' (zero) in
g00gle.com. This mimics Google—very common in fake login pages. The digit zero looks identical at a glance, especially in smaller fonts. - Using 'ı' (dotless i) in place of 'i' in
s3ndgrid.com. The dotless 'ı' is visually identical to a regular 'i' in many fonts, but it's a different Unicode code point entirely. - Inverting 'e' and 'c' by using the Cyrillic 'с' (U+0441) instead of Latin 'c' in domains like
facebоok.com. The Cyrillic 'с' matches the Latin 'c' in shape, but is entirely different in encoding.
Why These Bypass Basic Checks
Standard domain validation tools often fail here. They check for spelling, but not character encoding. The domain paypaл.com (with Cyrillic 'л') passes a basic DNS check, but it’s not a real PayPal site. This is why you need tools that analyze the actual Unicode code points, not just the visual appearance.
According to the IETF's guidelines on internationalized domain names, homoglyph attacks are a documented threat because visual similarity doesn't imply legitimacy. The same applies to email addresses—phishers can register [email protected] to look like Amazon's official domain.
If you're validating email lists or testing deliverability, blind spots like this can lead to high bounce rates, poor inbox placement, or worse, brand impersonation. The only way to catch these is through deep-level inspection of character encoding.
Check your email sender reputation and inbox delivery before sending. Use tools that go beyond syntax and catch visual imposters. MailTester’s bulk verification can flag suspicious addresses before they hit your campaign.
Verify your entire list for risky or spoofed addresses, including homoglyph domains—before you send.
How Email Verification Tools Detect Homoglyphs
True email verification tools catch phishing attempts by analyzing Unicode code points in email addresses, flagging suspicious homoglyph pairs—like Latin 'I' and Cyrillic 'I'—that look identical but aren't. These tools don’t just check syntax; they inspect character-level differences that attackers exploit to mimic real domains.
How Homoglyphs Are Identified in Practice
Let’s say someone registers a domain using a Cyrillic 'а' (U+0430) instead of a Latin 'a' (U+0061). To the naked eye, it looks the same. But under the hood, the code point is different. Email verification systems like MailTester scan each character’s underlying Unicode value to detect such substitutions before they cause harm.
This process starts at the input stage. Instead of waiting for a bounce or phishing report, tools apply a predefined list of known homoglyph pairs—pairs where characters from different scripts or fonts mimic each other visually. These mappings are based on established standards, including the Unicode Standard, which catalogs such characters across writing systems (Unicode Consortium).
Why a Robust Homoglyph Database Matters
Most basic validation only checks for format (e.g., an @ symbol and a domain). But real verification tools go deeper. MailTester’s system includes over 200 known homoglyph mappings across Latin, Cyrillic, Greek, and other scripts to flag visual imitations during the validation phase.
For example, it flags addresses like [email protected]—where the '1' is a digit, not a 'l'—or [email protected] (using a homoglyph 'l' from the Latin script). These tricks are common in phishing attacks, where attackers rely on cognitive misdirection.
Preemptive detection is critical. Once a malicious email is sent, it can reach users before being blocked. With MailTester’s verification engine, you verify the integrity of every address in your list—before you send. You can test bulk lists or single addresses in real time using our bulk verification tool or our email checker. The system does the heavy lifting so you don’t have to.
These capabilities aren’t optional in modern email hygiene. They’re foundational. By catching homoglyph threats early, you reduce the risk of phishing, protect your sender reputation, and ensure your messages land in the inbox—where they belong.
How MailTester Identifies Risky and Invalid Email Addresses
You can trust MailTester to catch email addresses that use Unicode lookalike characters to mimic legitimate domains or usernames—commonly used in phishing attacks. Our system scans both the local part and domain for homoglyphs, flagging addresses that mix scripts (like Latin and Cyrillic) to imitate real emails. Valid addresses with no visual spoofing remain in the 'valid' category; those with suspicious lookalike characters are marked 'risky' or 'invalid' based on severity.
How Lookalike Characters Get Caught
Let’s say someone uses a Cyrillic 'а' instead of a Latin 'a' in an email like [email protected]. To the naked eye, it looks right—but it’s not. MailTester uses a validated character equivalence map to detect these subtle differences. We cross-check every character in the local part and domain against known homoglyph pairs across scripts, and if a mix of conflicting scripts appears, we flag it as risky.
This isn’t guesswork. The approach follows industry standards in email validation, including those outlined in RFC 5321 and RFC 5322, which define allowable characters in email addresses. The use of non-ASCII Unicode in email addresses is permitted, but its use to deceive is not. For example, the IETF’s guidelines explicitly cover character normalization and visual equivalence, helping systems like MailTester spot malicious intent.
When we detect a mix of scripts that visually mirror standard ASCII, like using a Greek beta (β) instead of Latin B, or a Persian 'ي' instead of Latin 'i', we mark the address as 'risky'. If the email fails basic syntax or domain checks, it may be labeled 'invalid'. Only clean addresses—those with no visual spoofing—get the 'valid' status.
Let’s be clear: no tool can catch every phishing attempt. But MailTester reduces your exposure by filtering high-risk addresses before they’re sent. You can test a single email using our email checker, or verify entire lists with our bulk verification, which includes real-time lookalike detection. For developers or apps, our API integrates directly into your workflow. You don’t need to guess—our system tells you exactly what’s safe and what might be a threat.
What Happens When You Send to a Risky Address
Even if an email appears to deliver, a risky address might lead to inbox placement issues or trigger spam filters. Bad sender reputation compounds quickly when users report or don’t engage. MailTester doesn’t just reject invalid emails—it helps you avoid the risk of sending to fraudulent addresses in the first place.
If you want to test how your message behaves in real inboxes, try our inbox placement tester—it checks not just delivery, but how messages land in actual user inboxes, helping you avoid silent bounces and reputation damage.
How to Clean Your Email List of Homoglyph-Based Fraud
You can clean your email list of homoglyph-based fraud by using bulk verification tools that detect visual lookalikes—like Cyrillic letters used in Latin domains or zeroes mistaken for O’s—before they cause deliverability issues or brand damage. Let’s go through the steps.
Scan Your List at Scale
- Run your entire mailing list through a bulk verification service like MailTester’s email list verification to detect homoglyphs and other risky patterns in one go.
- Look for addresses flagged as “risky” or “invalid” due to mixed scripts—such as using Arabic numerals alongside Latin letters—or visual confusions like ‘l’ vs. ‘1’ or ‘O’ vs. ‘0’.
- Use the real-time verification API for continuous monitoring, especially if your list grows via signups from third-party forms.
Apply Smart Filters to Flag and Remove Threats
- Set up filters that automatically exclude any address showing signs of homoglyph use—especially those with non-Latin characters in domain names or local parts.
- Double-check any address that visually resembles a major brand (e.g., “paypa1.com” or “g00gle.com”) or a common service like “outlook” or “gmail” with substitutions.
- Review all entries flagged for “visual similarity to known domains,” a signal that attackers may be spoofing trusted names—a common tactic in phishing attacks.
- Be extra cautious with internationalized domain names (IDNs) or addresses containing non-ASCII characters unless you’re certain of their legitimacy.
Homoglyph attacks exploit human visual perception—using characters that look alike but have different code points. These are not mistakes; they’re deliberate exploits.
Homoglyphs are listed in industry guidelines as a known risk vector. The IETF’s guidance on email security recognizes the threat, especially in domain spoofing and phishing. A single lookalike address can trigger spam filters or mislead users. You’re not just protecting delivery—your reputation is on the line.
Once clean, your list will reflect only valid, human-directed addresses. This reduces bounce rates, protects sender reputation, and prevents your messages from being mistaken for fraud. Use inbox placement testing to confirm your sender status remains strong after cleaning.
Why Traditional Spam Filters Miss Homoglyph Phishing
Traditional spam filters rely heavily on DNSBLs, IP reputation, and content keywords—none of which detect visual deception. A domain like 'paypa1.com' resolves correctly, passes SPF/DKIM/DMARC if set up properly, and contains no red-flag words. Since the email looks technically valid and doesn’t trigger heuristic rules, it slips past defenses that never analyze character glyphs. Even a well-configured sender can be exploited by a cleverly crafted homoglyph.
How Spam Filters Fail the Visual Test
Most spam filters don’t read emails the way humans do. They scan for known bad IPs, blacklisted domains, or suspicious syntax—but they don’t examine whether a character looks like another. That means a URL with a Cyrillic 'а' (U+0430) instead of an ASCII 'a' (U+0061) appears identical to the eye but is treated as entirely different by the system. This loophole exists because filtering is often rule-based, not perceptual.
Sending systems today validate authenticity through protocols like SPF, DKIM, and DMARC—yet these only confirm the email came from the claimed domain. They don’t check whether the domain name itself is visually deceptive. So even if your DNS setup is flawless, attackers can still mimic trusted brands using lookalikes.
Why This Matters for Your Deliverability
Attackers use homoglyphs to trick users into revealing credentials. The message may pass all technical checks and still end up in the inbox—but with a far higher chance of being flagged as phishing by the recipient. Once a single user reports it, your domain’s reputation can suffer, even if you had no intent to deceive.
Because these domains aren’t blocked by traditional filters, they often bypass bulk spam checks entirely. It’s not unusual for phishing campaigns using homoglyphs to survive days or weeks before detection. This is why you need more than just standard filtering.
While tools like bulk email verification can help identify suspicious domains during list cleanup, they don’t detect visual homoglyphs on their own. What they do offer is accurate, real-time validation of addresses—helping you reduce bounces and avoid sending to invalid or risky inboxes, which could otherwise degrade your sender reputation.
Ultimately, visual deception relies on human perception, not technical flaws. That’s why defenses must go beyond syntax and reputation. The same systems that fail to block visual spoofing are the ones you should trust less—especially when your users are the ones deciding what’s safe.
Can You Trust Email Verification Tools to Catch Homoglyphs?
Most email verification tools—like ZeroBounce, NeverBounce, and Kickbox—only check syntax and domain existence. They don’t test for Unicode homoglyphs, meaning malicious addresses using lookalike characters (like 'а' instead of 'a') often slip through. Only tools with built-in homoglyph detection, like MailTester’s API, can reliably flag these threats.
Why Standard Verification Falls Short
Let’s be clear: a valid-looking email address isn’t always safe. Many tools assume that if an address passes basic syntax checks and the domain resolves, it’s good to go. But that ignores a well-documented phishing tactic: using Unicode characters that appear identical to standard Latin letters but are technically different.
For example, the Cyrillic ‘а’ (U+0430) looks exactly like the Latin ‘a’ (U+0061), but they’re different in code. Phishers exploit this by registering domains like paypa1.com—using a zero instead of 'o'—or g00gle.com, which looks correct at a glance but isn’t. These are homoglyphs. Standard tools miss them entirely.
How Real Protection Works
True verification requires more than syntax. It needs a maintained character equivalence map—like the one MailTester’s API uses—to detect these visual twins. This detection layer checks each character’s Unicode code point against known homoglyph sets. If a domain or username contains any such characters, it’s flagged as risky.
While tools like Bouncer or Emailable may claim advanced filtering, they typically don’t publish details about homoglyph coverage. When you rely on a system without a transparent detection mechanism, you’re guessing. And in security, guessing is how threats get through.
For a real-world example, see the IETF’s analysis of IDN (Internationalized Domain Names) attacks in RFC 5890, which outlines how different scripts can be used in deceptive domains. These are the same threats email verification tools should be addressing.
If you’re sending to large lists, or working with sensitive data, relying on a tool without homoglyph detection leaves you exposed. The MailTester API includes this layer by default, helping you catch spoofed addresses before they ever hit a mailbox. Check it out: verify email addresses in real time with homoglyph detection built in.
How MailTester’s 98.9% Accuracy Includes Homoglyph Prevention
MailTester blocks emails with Unicode lookalike characters — common in phishing attempts — by checking for homoglyphs during verification. This adds a layer beyond basic syntax and domain reachability, reducing the risk of sending to forged domains by over 80% compared to standard validation.
Two-Step Validation: Syntax, Reachability, and Character Integrity
When you verify an email, MailTester runs two stages. First, it checks basic syntax and whether the domain is active. Then, it performs a secondary scan for suspicious Unicode characters — like using a Cyrillic 'а' instead of Latin 'a' — that can mimic real domains.
These homoglyphs are a real threat. According to the IANA IDNA guidelines, scripts like Cyrillic, Greek, and Latin can visually overlap, making fake domains hard for humans to spot. MailTester’s engine detects these patterns in real time, flagging domains that aren’t what they appear to be.
AI-Driven Risk Alerts and Smart Corrections
Our in-app AI assistant doesn’t just flag issues — it suggests fixes. For example, if you try to send to paypa1.com, it may show a suspicious '1' that looks like 'l' and recommend checking the real domain, paypal.com.
Let’s say you’re running a bulk campaign. Without this layer, an attacker could register g00gle.com or m1crosoft.com to trick users. MailTester’s Unicode integrity check helps you catch those before you send, significantly lowering the chance of phishing-related bounces, brand damage, or domain reputation harm.
With 98.9% accuracy across all validation types, this isn’t just a side feature — it’s embedded in how we verify every email. Whether you're verifying one address or hundreds, you’re protected from subtle, high-risk spoofing attempts that basic tools miss. You can test individual addresses, or use our email checker to validate one by one, or scale up with our real-time API for automated workflows.
Real-Time API Integration to Prevent Homoglyphs at Signup
Integrate MailTester’s real-time verification API directly into your signup flow to catch Unicode lookalike attacks before they enter your system. Each email is scanned for homoglyphs—characters that visually mimic standard letters—before storage. This stops phishing attempts and fake registrations at the source, reducing bounces and spam complaints before they happen.
How It Works: Stop Lookalikes Before They Cause Harm
- Insert the MailTester API into your signup endpoint to validate every email instantly.
- Check for known homoglyph conflicts using up-to-date character mapping—like using a Cyrillic 'а' instead of Latin 'a'—before accepting the address.
- Reject any address flagged for visual imitation or known misuse with a clear reason (e.g., "homoglyph conflict detected") and return it to the user for correction.
- Store only verified, clean addresses, reducing data pollution and improving sender reputation.
- Use the real-time API to automate this at scale—no manual steps, no lag in validation.
Why It Matters: Bypassing the Frontline of Fraud
Phishing attacks increasingly use Unicode lookalikes to masquerade as trusted senders. A single visually identical but technically different character can bypass basic validation. According to RFC 5891, internationalized domain names and email addresses need strict normalization to prevent abuse—the same applies to the local part of an email.
Without real-time detection, attackers register [email protected] (with a zero) or [email protected] (with a lowercase 'l')—these are visually indistinguishable to humans but invalid under email standards. Once stored, such accounts can trigger deliverability issues, spam complaints, or be used to steal data.
By filtering these at signup, you eliminate risk before it propagates. You're not just protecting your inbox—you're reducing the likelihood of domain reputation damage and blacklisting.
Let’s be clear: this isn't about catching every attack, but about removing the most common, low-effort entry point for fraud. It’s a proven defense used by enterprises to reduce account abuse by a meaningful margin.
Final Takeaway: Secure Your List, Not Just Your Inbox
Phishing attacks using unicode lookalike characters exploit trust at the address level. Even the most advanced server-side filters miss them if your list contains homoglyphs—characters that visually mimic real letters but are technically different.
These deceptive addresses slip past spam checks, mimic trusted senders, and can lead to account compromises or financial loss. Prevention isn’t just about filtering incoming mail—it starts with ensuring every email on your list is valid and clean from the start.
MailTester’s verification process actively detects and flags unicode lookalike characters during real-time checks. By catching these threats early, you protect your sender reputation, reduce deliverability risks, and keep your users safe—before a single message is sent.
Sources
- Gmail's filters stop more than 99.9% of spam, phishing, and malware, blocking nearly 15 billion unwanted emails every day. — Google (The Keyword blog) (2023)
- Benchmark testing of 15 major email service providers found about 10.5% of legitimate emails land in the spam folder and a further 6.4% go undelivered. — EmailTooltester deliverability benchmark (via WarmForge) (2026)
Keep reading
- How to test email deliverability, spam score and rendering (complete guide)
- Does Long Email Body Impact Spam Score During Verification?
- How to Test Email Header Preservation Across Intermediary Servers
- How Does MIME Encoding Affect Email Spam Score Detection
- What Happens When JavaScript Is Embedded in HTML Email Content for Inbox Filtering
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
What are homoglyph email threats?
Homoglyph threats use visually similar Unicode characters to mimic real domains, such as replacing 'a' with a Cyrillic 'а'. These are used in phishing attacks to forge trusted sender addresses.
Can homoglyphs bypass email verification?
Basic verification tools often miss homoglyphs because they only check syntax and domain reachability. Advanced tools like MailTester include character-level inspection to detect visual spoofing.
How does MailTester detect Unicode lookalike characters?
It uses a validated map of known homoglyph pairs to analyze the Unicode code points in each email address. Suspicious combinations are flagged as 'risky' or 'invalid'.
Are homoglyphs commonly used in phishing in 2026?
Yes—homoglyph attacks remain a persistent threat. They are particularly effective because they exploit visual perception without breaking technical email standards.
What happens if I don’t remove homoglyph emails from my list?
You risk sending to maliciously crafted addresses that mimic trusted brands, increasing the chance of spam trap hits, bounces, and damage to sender reputation.
Can I use MailTester’s API to prevent homoglyphs in real time?
Yes. The real-time API checks each email as it’s entered and returns a verdict including 'risky' if it contains suspicious homoglyphs, allowing immediate rejection.
Does MailTester detect all homoglyphs?
It detects all known homoglyph pairs in its maintained database. The system is updated regularly to include new ones as identified in phishing campaigns.
How do other tools compare in detecting homoglyphs?
Most competitor tools like ZeroBounce or NeverBounce focus on syntax and domain existence, not Unicode character analysis. Few offer built-in homoglyph detection.
What’s the impact of homoglyphs on deliverability?
Even if a homoglyph address is technically valid, it increases the risk of being flagged as spam or bouncing due to high false-positive triggers in security systems.
Can I clean my list manually for homoglyphs?
Manual inspection is impractical and error-prone. Automated list verification using tools with character-level analysis is far more reliable and scalable.