Phishing attackers don't only forge email content — they forge the domain itself, swapping a Latin letter for a Cyrillic or Greek lookalike, or a digit for a letter, so the URL passes a glance at first read. This simulator renders a trusted brand domain and a candidate domain as two rows of character tiles on a flat scan field, then runs a confusable-aware Levenshtein alignment between them — the same skeleton-matching idea (Unicode Technical Standard #39) that real brand-protection and mail-gateway filters use. Color-coded beams trace the character alignment, an expanding scanner ripple sweeps the field and a status beacon shifts color with the verdict, a live similarity score and confusable-character count update as you switch between real-world lookalike pairs, and an adjustable threshold shows exactly where a detector would draw the line between "flag it" and "let it through." A punycode (RFC 3492 / IDN) panel shows the ASCII-safe form a browser's address bar would actually resolve. Drag to pan and scroll to zoom in on longer combosquatted domains.