← All tools

Security · Free · In your browser

Homoglyph Detector

Find Cyrillic, Greek, and other look-alike characters disguised as ordinary Latin letters - the trick behind spoofed domains and phishing.

Homoglyphs are characters from different scripts that look identical to Latin letters (like Cyrillic “а” vs Latin “a”) and are used to disguise text.


Detect
⚙ Script filters

Choose which look-alikes to flag & normalize.

Paste your text

Paste text - we'll find any Cyrillic, Greek or fullwidth letters disguised as English. Try an example:

🔒 Nothing leaves your browser.

0 chars scanned

Click any flagged glyph to keep it (e.g. a real name) out of normalization.

- % Latin

Confusability

Paste text to scan

What we found

    🔒 Runs entirely in your browser - open DevTools → Network and you'll see zero requests. Works offline.

    No upload No signup Works offline Network requests this session: 0

    The short version


    How to use it

    1. Paste the text or string you want to check.
    2. See every confusable character flagged with its real identity.
    3. Replace or remove the imposters.

    Private by design

    There is no server and no upload. Everything runs with plain JavaScript on your device, so you can safely work with confidential or unpublished text. Open your browser's DevTools Network tab while you use it and you'll see zero requests - and it keeps working with your connection turned off.

    Related reading

    In the margin

    Frequently asked questions

    What is a homoglyph attack? +

    Swapping a normal Latin letter for an identical-looking character from another script - for example a Cyrillic “а” in place of “a”. It’s used to spoof domain names and slip past filters. The detector reveals exactly which characters aren’t what they seem.

    Why would text contain confusable characters? +

    Sometimes by accident (copying from another language), sometimes deliberately to evade detection or impersonate a brand. Either way, this tool shows which characters are mixed-script imposters.

    Is my text uploaded or stored anywhere? +

    No. Everything runs in your browser with plain JavaScript - your text is never uploaded, stored, or logged. Open your browser’s DevTools Network tab while you use it and you’ll see zero requests. The tool also works offline.

    Related tools

    Margin note

    Every tool here runs 100% in your browser. Open DevTools → Network while you use one and you'll see zero requests - your text never leaves your device. Prefer the deep dives? Read the writing on Penluma.