Free tool / no signup

Unicode Homoglyph Detector

Find characters that look like ordinary Latin letters but are not - the Cyrillic “а” inside a domain name, the Greek “ο” in a brand, the mixed-script word in a phishing link.

Runs on your device — nothing is uploaded
When you need this

What people use it for.

Checking a domain, sender name or link before you trust it, where one swapped letter is the whole attack
Reviewing a username or display name that impersonates someone else’s
Auditing a package, repository or dependency name for a look-alike typosquat
Working out why a string that looks identical to another one will not match it in code or a search
How it works

What happens to your text.

Every character is read and compared against a table of confusables - characters from other scripts that are drawn like a Latin letter. Each match is reported by name and code point and marked where it sits in the text. Then the text is read again word by word: any word that mixes Latin with Cyrillic or Greek is flagged as a mixed-script token, because a single foreign letter dropped into an otherwise Latin word is the shape almost every impersonation attack takes. The character map shows the result character by character, so you can see which one it is rather than being told a count. Everything runs in your browser and nothing is uploaded.

Where it stops: A match is a warning, not a verdict. Genuinely multilingual text mixes scripts for ordinary reasons, and a Russian or Greek word in an English sentence is flagged the same way a spoofed domain is - the tool cannot tell intent, only that the mixture is there. It compares against a table of known confusables, so a pair that is not in that table is not reported. It reports; it does not rewrite, because substituting letters inside a word you did not write is how real text gets corrupted.

Questions

Common questions.

What is a homoglyph?

A character from one alphabet drawn almost identically to a character from another. Cyrillic “а” (U+0430) and Latin “a” (U+0061) are different characters that look the same in most fonts, so “аpple” and “apple” are visually identical and completely different strings.

Why does a domain with a homoglyph matter?

Because the address bar shows you a name you recognise while the request goes somewhere else. It is the mechanism behind a large share of phishing links, and it is invisible by design - the only way to see it is to check the characters rather than the shapes.

Does this flag normal text in other languages?

It flags any word mixing Latin with Cyrillic or Greek, so a Russian or Greek word inside an English sentence is reported. That is correct behaviour for a detector: it tells you the mixture exists and leaves the judgement to you.

Can it fix the characters it finds?

No, deliberately. Replacing letters inside words is how legitimate multilingual text gets damaged, and the right response to a spoofed domain is not to rewrite it but to not follow it. To strip invisible characters rather than look-alike ones, use the hidden character remover.

Is my text uploaded?

No. The comparison runs in your browser and the text is never sent to a server.

Need the complete analysis?

The main WordMark sanitizer combines character forensics, statistical analysis, protected-data checks, alternatives, diffs and reports in one view.

Open full sanitizer
Related free tools

You might also need.