Firefox Browser Add-ons
  • Extensions
  • Themes
    • for Firefox
    • Dictionaries & Language Packs
    • Other Browser Sites
    • Add-ons for Android
Log in
Preview of URL Lookalike Blocker

URL Lookalike Blocker by Aussiefeld

Protects against IDN homograph attacks by blocking or warning when a domain contains characters from scripts you have not permitted, or characters that visually resemble a different character.

Available on Firefox for Android™Available on Firefox for Android™
0 (0 reviews)0 (0 reviews)
Download Firefox and get the extension
Download file

Extension Metadata

Screenshots
About this extension
Protects against IDN homograph attacks - attempts by attackers to register domain names that look identical to legitimate sites by substituting visually similar characters from other Unicode scripts (for example, Cyrillic a (U+0430) in place of Latin a).

When you navigate to a URL, the extension decodes the hostname from punycode and checks every character. Three things can happen:
  • Blocked: a character belongs to a script that is not in your permitted set.
  • Warning: all characters are permitted, but either (a) the label contains a known confusable character that mimics a Latin letter in a mixed-script context (highlighted red with "Looks like: ..."), or (b) the label mixes characters from two or more scripts in a way that is not common for any single language (highlighted amber, with a hint suggesting which language to enable if the combination is legitimate).
  • Allowed: everything checks out.

Blocked and warning pages show the punycode and Unicode forms of the domain, and a table of every suspicious character with its Unicode codepoint, script, and what it visually resembles.
From a blocked page you can allow the domain permanently, go back, or open settings to enable the required language. If you open settings from a blocked page, clicking Apply automatically retries the blocked URL.

From a warning page you can allow the domain permanently, continue for this browser session only, go back, or open settings.

The Options page (opened from the toolbar icon) lets you enable additional permitted languages, manage your whitelist of trusted domains, and adjust interface options. Compact mode (on by default on phones) collapses the language table and whitelist into concise read-only summaries with Edit buttons, keeping the page manageable on smaller screens. Language and whitelist changes are held in memory until you click Apply — there is no auto-save for security-relevant settings. Interface options (Show shadows, Show private-browsing warning, Compact mode) take effect instantly.

Multiple blocked or warning tabs at once are tracked with a numeric badge on the toolbar icon and coloured rounded squares in the Options page, so you can switch between them and resolve each one. Resolved or closed tabs clear from the badge automatically.

The Help page with screenshots and explanations of every feature is available from the toolbar icon's right-click menu.

Themes: light, dark, or follow-system, with a toggle on every extension page.

Known limitations:
- The extension detects single characters that look like a different character. It does not detect multi-character sequences that resemble one character (e.g. rn -> m, vv -> w, cl -> d), as doing so without a list of known legitimate domains would cause too many false positives.
- It does not detect lookalike domains constructed entirely from one script (e.g. a Latin-only domain designed to visually mimic another Latin domain). Protection is specifically against cross-script substitution attacks (IDN homographs).
- It does not detect subdomain-style phishing where a legitimate-looking name appears as a subdomain of an attacker-controlled domain (e.g. apple.com.attacker.com). That domain is Latin-only and passes all script checks correctly.
Rated 0 by 0 reviewers
Log in to rate this extension
There are no ratings yet

Star rating saved

5
0
4
0
3
0
2
0
1
0
No reviews yet
Permissions and data

Optional permissions:

  • Access your data for all websites

Data collection:

  • The developer says this extension doesn't require data collection.
Learn more
More information
Add-on Links
  • Homepage
  • Support site
  • Support Email
  • Copy add-on ID
Version
1.2.1
Size
1.09 MB
Last updated
18 hours ago (Jun 14, 2026)
Related Categories
  • Privacy & Security
License
Mozilla Public License 2.0
Privacy Policy
Read the privacy policy for this add-on
Version History
  • See all versions
Tags
  • dark mode
  • security
Add to collection
Report this add-on
Go to Mozilla's homepage

Add-ons

  • About
  • Firefox Add-ons Blog
  • Extension Workshop
  • Developer Hub
  • Developer Policies
  • Community Blog
  • Forum
  • Report a bug
  • Review Guide

Browsers

  • Desktop
  • Mobile
  • Enterprise

Products

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • Privacy
  • Cookies
  • Legal

Except where otherwise noted, content on this site is licensed under the Creative Commons Attribution Share-Alike License v3.0 or any later version. Android is a trademark of Google LLC.