IDN/Punycode Phishing Detector
Identify domain homograph attacks using Punycode and Unicode characters.
Runs in your browser Your input never leaves your device.
About this tool
Gives a quick first look at domain names that may use look-alike characters. Enter one or more domains separated by spaces, commas or new lines. Any xn-- Punycode label is decoded so you can see the real Unicode characters, and Unicode names are also shown in their ASCII (Punycode) form. The tool flags xn-- labels, non-ASCII characters, labels that mix scripts (for example Latin with Cyrillic or Greek), labels written entirely in Cyrillic or Greek using letters that resemble Latin ones, and full-width or mathematical look-alike characters. It is a simple heuristic, not a security product: it does not know the full Unicode confusables list, and a plain ASCII result does not mean a domain is safe (rn versus m, for example). Checks run in your browser.
How to use it
- Paste or type one or more domains.
- Read the flags listed under each domain.
- If a domain shows xn--, read the Unicode form the tool prints and compare it with the brand you expect.
- Treat any flagged domain with suspicion and check where the link came from.
Example
xn--pple-43d.com, apple.com
xn--pple-43d.com: Unicode form: аpple.com ASCII (Punycode) form: xn--pple-43d.com - contains Punycode label (xn--) - ⚠ label "аpple" mixes scripts (Cyrillic + Latin): possible homograph apple.com: plain ASCII, no IDN markers
Common problems
- A suspicious domain shows no warning
- Only script mixing, whole-script Cyrillic/Greek look-alikes, full-width and math characters are checked. Spelling tricks such as rn instead of m, or single-script look-alikes from other scripts, are not detected.
- A legitimate international domain is flagged
- Many real sites use non-ASCII or Punycode names. The flags mean look closer, not that the domain is malicious.
- Domains run together
- Separate entries with spaces, commas or new lines.