You read the email twice and it looks perfect: the logo, the prize, the "You're a finalist!" subject line. So you click, and the address bar says walmart-sweeps.com or amaz0n-rewards.com โ€” one character off from the brand you trust. That single swapped letter is the whole scam. Sweepstakes fraudsters don't hack real companies; they just register a domain that looks like the real one and wait for excited entrants to stop reading carefully.

Typosquatting and homoglyphs: how one letter does the work

Typosquatting is registering a domain built on a predictable mistake โ€” a doubled letter (gooogle), a dropped one (amazn), a swapped .com for .co, or an added word like -official, -promo, or -giveaway bolted onto a real brand. A domain costs about $10, so a scammer can buy dozens of near-misses for a single campaign and rotate through them as each gets reported and taken down.

Homoglyph attacks go a step nastier: they swap in characters that render almost identically. A capital I for a lowercase l, a zero for a capital O, or non-Latin Unicode letters โ€” a Cyrillic "ะฐ" looks exactly like a Latin "a" but sends you somewhere completely different. Your eye reads apple.com; the browser reads a different address entirely. This is why "it looked right" is never proof, and why you have to check the URL structurally instead of just glancing at it.

Read the URL right-to-left to find the true domain

Here's the one skill that beats every lookalike: find the real registered domain by reading right-to-left from the first single slash. The true owner of a web address is the two labels immediately before that first / โ€” the name plus the .com, .net, or .org. Everything to the left of those two labels is a subdomain the scammer fully controls and can name anything they want.

So walmart.giveaway-claim.com/win is not Walmart โ€” the registered domain is giveaway-claim.com, and "walmart" is just a subdomain dressed up to fool you. Compare that to giveaway.walmart.com, which really is Walmart, because walmart.com sits in the owner position. Watch for the @ trick too: in walmart.com@scam-site.ru, everything before the @ is ignored and you land on scam-site.ru. Read right-to-left, stop at the first slash, and the imposter has nowhere to hide.

Confirm the official address before you type anything

Never trust the link in the message to tell you where the message is really from. Open a new tab and reach the brand yourself โ€” type the address you already know, or search the company name and go to the result you recognize, then look for the promotion on their own site. If a real sweepstakes exists, it will be posted there; if the "finalist" email points to a domain the company never mentions, that mismatch is your answer.

Two more free checks take under a minute. Run the suspect domain through a WHOIS lookup (whois.domaintools.com or ICANN's lookup): a legitimate national sweepstakes rarely runs from a domain registered three days ago with hidden ownership. And check the official rules โ€” real US sweepstakes must name the sponsor and a physical address, and that sponsor should match the domain you're being sent to. ๐Ÿ”

Before you enter anything, read the URL right-to-left, confirm the domain on the brand's own site, and if a single character feels off, close the tab.