---
title: "How to prevent Phishing using Twisted Domains search?"
canonical: "https://kb.cynergy.app/space/GS/940670977/How%20to%20prevent%20Phishing%20using%20Twisted%20Domains%20search%3F"
format: markdown
---
Twisted domain names are a common tactic used by cybercriminals to trick people into visiting fraudulent or malicious websites. These websites are often used for phishing attacks, which are a type of cybercrime where attackers try to obtain sensitive information such as login credentials or financial information by pretending to be a legitimate entity. 

**What is a Twisted Domain Name? **

A twisted domain name is a type of domain name that appears legitimate at first glance, but is actually designed to mislead or deceive the user. These domain names often use characters that look similar to letters in the English alphabet, but are actually different Unicode characters that are difficult to distinguish from regular letters. For example, a twisted domain name might use the Cyrillic letter "a" instead of the Latin letter "a", or the Greek letter "φ" instead of the Latin letter "f".

**How Twisted Domains are used by threat actors?**

Twisted domain names are often used in phishing attacks because they can be registered and used to host fraudulent websites that look almost identical to legitimate websites. This makes it easy for attackers to trick people into visiting these sites and entering their sensitive information.

To protect yourself from phishing websites that use twisted domain names, it is important to use a twisted domain name scan tool. Cynergy is designed to identify twisted domain names and alert you once they are introduced to the web.

To use a twisted domain scan with Cynergy, you can run two different methods:

1. Run a [discovery scan ](https://kb.cynergy.app/space/GS/899416424/How+to+configure+your+first+scan+in+Cynergy%3F)
2. Use the Cynergy API and get all the associated Twisted Domain names to the requested domain.

![image](media://b2b48cda-9f88-40e1-9324-b48f0dc6b1f8)


Once the scan is finished, you will get the list that includes:

1. Twisted Domain Name
2. IP addresses - Associated IP addresses to the twisted domain
3. MX records - Relevant MX record
4. Type of twist - The type of permutation
5. Location - Geolocation of the IPs
6. The similarity in percentage - the similarity of the content they present to the content of your main websites. A higher similarity represents a higher chance that the Domain is used for Phishing.


An example of a Twisted-domains scan is below.

![image-20240310-084830.png](media://9e00e2c1-1ae6-44cb-8f57-c51de564e2d6)

> ℹ️ It should be noted that if the original Top Level Domain can’t be resolved. Than there will **not** be any results for the twisted domains.


**What else could you do to prevent Phishing?**

In addition to using Cynergy, there are a few other steps you can take to protect yourself from phishing attacks:

1. Be cautious when clicking on links in emails or online. Only click on links from trusted sources, and be suspicious of links that seem too good to be true or that ask you to enter sensitive information.
2. Use strong, unique passwords for all of your online accounts. Avoid using the same password for multiple accounts, and use a password manager to help you generate and store strong passwords.
3. Keep your software and devices up to date with the latest security patches and updates. This will help to protect against vulnerabilities that attackers could exploit.

By using Cynergy’s twisted domain name scan and following these best practices, you can help to protect yourself from phishing attacks and other cyber threats. Stay safe online!