Punycode Converter
Convert xn-- punycode domains to Unicode and back, and see when an internationalised domain is imitating a well-known name.
How to use
- Paste a domain, a URL or a whole email — every xn-- domain in it is converted.
- To go the other way, choose “Unicode → punycode” and paste the Unicode domain.
- Check the look-alike warnings under the input.
Steps
Output
How internationalised domains are stored
DNS only carries letters, digits and hyphens. A domain such as bücher.example or 例え.jp is therefore stored label by label in an ASCII-compatible form: the prefix xn-- followed by the Punycode encoding of that label (RFC 3492). Labels that are already ASCII stay as they are, so only the internationalised parts change.
Converting to punycode also normalises the name the way browsers do (IDNA / UTS #46): capitals become lowercase and some characters are mapped to their standard form. Two names that look different in Unicode can therefore be the same domain.
Look-alike (homograph) domains
Several alphabets contain letters that look identical to Latin ones: Cyrillic а, е, о, р, с and Greek ο are the classic examples. xn--80ak6aa92e.com, a well-known demonstration, renders as a Cyrillic spelling that looks like apple.com. Mail filters and users who read the Unicode form see the brand; DNS sees an unrelated domain.
Paste a suspicious link or an entire email: every xn-- domain is converted in place, and names that imitate common brands or mix scripts are flagged above the output.
Email addresses and certificates
Only the domain part of an address is punycode; the part before @ is handled separately (SMTPUTF8) and is left untouched here. TLS certificates always contain the xn-- form, so convert it when you compare a certificate’s names with what the user saw.
Common questions
What does xn-- mean in a domain?
It marks a label that contains non-ASCII characters, stored in DNS as ASCII using the Punycode algorithm. xn--bcher-kva.example is the internationalised domain bücher.example.
Why does my browser show xn-- instead of the real name?
Browsers show the punycode form when a label mixes scripts or could be confused with another name. It is a deliberate defence against look-alike phishing domains.
Are punycode domains dangerous?
Not in themselves — millions of legitimate sites use non-Latin scripts. They become a phishing risk when the Unicode form imitates a familiar brand, which the look-alike check flags.
Known limitations
- Unicode → punycode uses your browser’s own URL parser, so it applies the same IDNA mapping (lowercasing and normalisation) your browser uses to resolve the name.
- The look-alike check covers common Cyrillic, Greek and Armenian substitutions, not the full Unicode confusables table.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- RFC 3492 — Punycode (opens in a new tab)
- RFC 5891 — IDNA2008 protocol (opens in a new tab)
- Unicode TR 46 — IDNA compatibility processing (opens in a new tab)
- Unicode TR 39 — confusable characters (opens in a new tab)
- Chromium — IDN display policy (opens in a new tab)