Loading network utility...
Loading network utility...
Learn how global DNS handles Unicode domain names through Punycode encoding, and how security teams detect homograph spoofing attacks.
Run live checks and calculations directly on LotsofNetwork.
The core Domain Name System (RFC 1034/1035) was engineered in the early 1980s with strict character limitations: domain labels could only consist of standard ASCII letters (A-Z), digits (0-9), and hyphens ('-'). This standard is known as the LDH (Letter-Digit-Hyphen) rule.
As web adoption spread worldwide, users demanded domains in their native scripts (Arabic, Cyrillic, Chinese, Japanese, and accented Latin scripts). Instead of breaking global DNS infrastructure, the IETF developed IDNA (Internationalizing Domain Names in Applications).
Punycode uses a Bootstring algorithm to uniquely and reversibly encode any Unicode string into standard ASCII. All IDN labels encoded with Punycode are prefixed with 'xn--' (the ASCII-Compatible Encoding, or ACE, prefix).
For example, the domain 'münchen.de' contains the non-ASCII character 'ü'. When encoded by the browser client, the ASCII label becomes 'xn--mnchen-3ya.de'. Global DNS root servers and authoritatives only ever resolve and route this ASCII representation.
| Original Domain | Punycode DNS Label (ACE) | Script Family |
|---|---|---|
| münchen.de | xn--mnchen-3ya.de | Latin Extended (German) |
| 中文.com | xn--fiq228c.com | Simplified Chinese (CJK) |
| россия.рф | xn--h1alffa9f.xn--p1ai | Cyrillic (Russian) |
| ❤️.ws | xn--qe8h.ws | Unicode Emoji |
Because different alphabets share visually identical glyphs (homoglyphs), attackers exploit IDNs for credential harvesting. For instance, the Cyrillic small letter 'а' (U+0430) looks identical to the Latin letter 'a' (U+0061). An attacker registering 'аpple.com' creates the Punycode domain 'xn--pple-43d.com'.
Modern web browsers prevent homograph spoofing by checking whether a domain uses mixed scripts or characters outside the user's configured language locale. If suspicious mixed scripts are found, the browser automatically displays the raw 'xn--' string in the address bar instead of rendering the Unicode text.
Always inspect the raw Punycode ACE string when verifying SSL certificates or suspicious email sender domains. If a domain claiming to be an American or European bank starts with 'xn--', it is likely a spoofed homoglyph.
Quick answers to common questions on this topic.
High-speed, zero-cost engineering tools built for network diagnostics and developer workflows.
Detect IP, GeoIP, ISP, ASN & PTR
Reverse IP to PTR hostname & verify FCrDNS
Query A, AAAA, MX, TXT & NS records
Domain registrar & expiry info
Calculate CIDR, masks & host ranges
Two-way CIDR notation to IP range converter