A lookalike domain does not have to survive inspection. It has to survive one glance from someone who is already busy — and it is designed against exactly that.
The four tricks
Characters that resolve to the same shape
A lowercase l and an uppercase I are the same vertical stroke in many
fonts. rn read quickly is m. A zero is an O. Nothing here needs
exotic Unicode; the ordinary alphabet has enough collisions.
Words in the wrong place
Only the part immediately before the ending is the real domain. In
yourbank.security-check.com the site is security-check.com, and
"yourbank" is decoration the attacker chose. Reading left to right and stopping at the first
familiar word is the exact habit being exploited.
A different ending on a correct name
The name is spelled perfectly and the ending is not the one you know. This is the hardest to catch, because there is nothing misspelled to notice. Endings vary enormously in how much abuse they carry — the statistics page shows the spread, and it runs from under one percent to over three quarters.
Plausible additions
-secure, -verify, -login, -support. These
read as reassurance and are the opposite. Real organisations do not spin up a separate domain
to host their login page.
Why inspecting links is the wrong defence
Every guide tells you to hover over the link and read the address. It is honest advice and it fails in practice, because the failure mode is not that you cannot read — it is that you are reading a message which has already convinced you something is urgent. Under time pressure people confirm what they expect to see, and the domain was chosen to be confirmable.
The habit that actually works
Do not follow links to anywhere that matters. Not in email, not in messages, not in adverts. When something claims to be your bank, your delivery company or your account, reach it the way you always do: your own bookmark, your own typing, the app on your phone.
This defeats all four tricks at once and needs no attention to detail — which is the point. It works precisely when you have no attention to spare. If the message was genuine, the same information is waiting when you arrive under your own steam.
When you do want to check an address you have been sent, paste it into the scanner rather than into the address bar. It resolves the domain, checks its age and registration and tells you what it found — without your browser ever going there.