Homograph attack
A spoofing technique that registers a domain name built from lookalike characters, often from another alphabet, so a fraudulent site or sender address looks legitimate at a glance.
A homograph attack exploits characters that look the same but are different. Internationalised domain names allow letters from many alphabets, and several Cyrillic and Greek letters are visually identical to Latin ones. An attacker can register a domain in which, for example, one Latin “a” is replaced by a Cyrillic “а”, so the name reads like a well-known brand. The name is stored in an ASCII form, encoded with Punycode (RFC 3492) and prefixed “xn—”, which reveals the substitution, but a user may see only the familiar-looking version.
The attack is a form of spoofing that slips past familiar controls. The fake domain is genuinely registered, so DNS resolves it correctly and DNSSEC can even sign it. The attacker can obtain a valid certificate, so the padlock of HTTPS appears. Email authentication such as DMARC can pass, because the lookalike domain is the attacker’s own. Defences therefore sit elsewhere: browsers that show Punycode for suspicious mixed-script names, registering lookalikes of one’s own domain, and user awareness.
Exam relevance: a scenario is likely to describe a phishing site that has a valid certificate and a correct-looking address. Candidates are expected to see that certificates and email authentication prove control of a domain, not that it is the domain the user intended.