Look-alike domain checker
A fake exchange's favourite trick is to change one or two letters in the official address, or slip in foreign letters that look identical. Paste the URL you're about to open and this tool takes it apart character by character, right in your browser — nothing is uploaded, nothing is logged.
This tool checks against Binance's official domain binance.com (and its subdomains, such as accounts.binance.com). It can help you spot something suspicious, but it cannot guarantee a site is safe. The safest habit is to bookmark the official site and enter through that bookmark every time — never from a search ad or a link in a chat message. Further reading: how to spot a fake exchange and the bookmark login safety rule.
Which kind of scam this tool helps you block
The whole fake-exchange con usually hinges on one thing: you think you've reached the real Binance site, but you've actually landed on a clone the scammers have parked on a similar address. The page can be copied pixel for pixel — the logo, the price charts, the login box are all genuine assets, and your eye can barely tell the difference. The one thing they can't copy is that line of text in the address bar. This checker goes after the small moves hidden in that line: swapped letters, an inserted hyphen, foreign look-alike characters standing in for ordinary ones, and phishing domains buried inside Punycode (xn--). It pulls the URL you paste apart character by character, lines it up against the official domain, and marks the differences your eye tends to skip over — so you can see who you're really dealing with before you type a password or send a deposit. For the full picture of how this kind of attack works, start with how to spot a fake exchange.
The right way to use it is simple: copy and paste the entire URL you're "about to click", not just the first few characters. What matters is always the rightmost part — the main domain plus its ending. Everything before that (subdomains, extra words, hyphens) is decoration. If the result looks suspicious, stop there. If it shows the official domain, take a moment anyway to confirm the connection is https and the address bar has no stray characters. Passing the check only means "this spelling matches the official one"; it does not mean the link itself is clean.