Your IP address:
Provider:
...

Punycode and internationalised domain names explained

Punycode is an encoding used to represent Unicode characters in an ASCII-compatible form for internationalised domain names. A domain written with national characters may therefore appear in technical data as a label beginning xn--. The encoding changes representation; it does not establish that a website is genuine.

Unicode labels and DNS labels

People may see a Unicode label, often called a U-label. Its ASCII-compatible counterpart is an A-label, which begins with xn-- when Punycode is involved. Each eligible label between dots is processed separately. The conversion does not encode an entire URL: scheme, path and query follow other rules.

For example, the IDN test label bücher has the A-label xn--bcher-kva. Both forms refer to the same domain label when processed under the applicable IDNA rules. Registries may have further restrictions on which labels can actually be registered.

Why the display can change

A browser may show the Unicode form for one domain and an A-label for another according to its security and language rules. Copying a URL into a diagnostic tool can therefore reveal an unfamiliar xn-- string. This is expected for many internationalised names and is not itself evidence of an attack.

However, characters from different scripts can look alike. A deceptive domain may resemble a familiar brand while having different underlying code points. Punycode faithfully encodes those characters; it does not detect impersonation, verify ownership or check a site’s content.

Checking a suspicious address

Read the complete host name, including the domain ending, before entering credentials. Compare it with a trusted bookmark or the organisation’s published address. Be careful with links in urgent messages, and check the certificate name when the browser reports a warning.

Conversion tools can show the Unicode and ASCII forms, but the conversion alone is not a safety verdict. Registration data may provide context, yet private or limited records cannot prove a sender’s identity. When in doubt, navigate independently to the service rather than following the questionable link.

When documenting a suspicious name, preserve both its Unicode and A-label forms. This prevents a copy-and-paste or font difference from hiding the exact domain that was visited.

When preserving evidence of a suspicious link, copy both the visible Unicode spelling and the corresponding A-label. A font difference or automatic link preview can conceal which characters were actually used. Also record the complete URL separately from the domain; a misleading path can appear below a legitimate host.