I want to show you something that's going to be a little unsettling, because the best way to understand this trick is to actually fall for it once, safely, right now.
Take a look at these two web addresses:

One of those is the real Microsoft website. The other one isn't — and I'd bet you can't tell which is which just by looking. That's not a trick of the eye. They are built, on purpose, to be impossible to tell apart.
This is called a homoglyph attack (sometimes called script spoofing or an IDN homograph attack, if you ever see those terms). The short version: a lot of different languages have letters that are written completely differently from our Latin alphabet, but every so often, a letter from another alphabet happens to look identical to one of ours. The Cyrillic letter "о," for example — the one used in Russian and several other languages — is drawn the same as our letter "o." Same shape, same size, same everything to the human eye. But to a computer, they are two completely different characters, as different as the letter "o" and the number "7."
Someone who wants to trick you can register a web address using one of these look-alike letters instead of the real one. The address in your browser looks perfect. The little padlock icon can even show up, because the fake site can have its own real security certificate — that padlock only means the connection is encrypted, not that you're talking to who you think you are. You land on a page that looks exactly like the real thing, log in like you always do, and you've just handed your password straight to someone else.

A quick, honest note on the example above: registrars have gotten better in recent years at blocking the most obvious version of this trick — registering an exact mixed-alphabet clone of a big, famous ".com" is harder to pull off than it used to be. But the same technique is alive and well through other channels: less-restricted domain endings, subdomains, similar tricks using ordinary Latin letters (like a lowercase "rn" that looks like an "m," or a "1" that looks like a lowercase "l"), and fake sender names in emails and text messages. The specific example is illustrative; the underlying trick is very real and still very common.
So how do you actually catch it? A few things that work, roughly from easiest to most bulletproof:
- Let your password manager do the checking for you. This is genuinely the best defense, and it's not even something you have to think about. A password manager doesn't recognize a website by its appearance — it checks the exact, literal address on file. If you land on a homoglyph copy of a site, your password manager simply won't offer to fill anything in, because as far as it's concerned, it's never seen this address before. That silence is your warning sign. If a login page ever asks you to type your password in by hand when it usually autofills, stop and look closely.
- Don't trust a link just because it "looks right." If a link comes to you in an email, a text, or a search result, and it takes you somewhere where you'll need to log in or enter payment information, type the address in yourself instead, or use a bookmark you saved earlier. Never trust your eyes alone with a URL — as we just proved, they can't actually do this job reliably.
- Know that the padlock icon isn't proof of anything except encryption. A lot of people were taught "look for the padlock" as the whole rule. It's not enough anymore. The padlock just means nobody can eavesdrop on the connection — it says nothing about who's actually on the other end.
- Turn on multi-factor authentication everywhere you can. If your password does end up in the wrong hands despite everything, MFA is what stops that from turning into a full account takeover. We've talked about this before, but it bears repeating here: it's one of the highest-leverage things you can set up once and benefit from constantly.
None of this requires you to become a computer scientist or to start reading URLs one character at a time — that's genuinely not realistic, and I wouldn't ask it of anyone. The real fix is simpler: know that this trick exists, trust your password manager's silence as a real warning, and get in the habit of typing important addresses yourself rather than clicking your way there. That one habit alone closes the door on almost the entire attack.
If you ever land on a page that feels almost right but something's off, that instinct is worth listening to — and if you want a second opinion, you know where to find me.
Stay sharp out there. Andrew