Crypto
Punycode / IDN Domain Converter
Convert Internationalized Domain Names (IDNs) containing non-ASCII Unicode characters (German umlauts, Cyrillic, Kanji) to DNS-compatible ASCII (xn--) and vice versa per RFC 3492 / RFC 5891 standards.
How to use
- Enter a domain, URL, or value relevant to Punycode / IDN Domain Converter.
- Run the check and review the output carefully.
- Apply recommended fixes, then run the check again to verify.
Common use cases
- Pre-deployment validation for Punycode / IDN Domain Converter.
- Incident triage when security checks fail in production.
- Periodic security review as part of technical SEO and hardening.
Example inputs
münchen.de → xn--mnchen-3ya.deкиїв.укр → xn--e1aybc.xn--j1amh日本語.jp → xn--wgv71a119e.jpCommon issues and fixes
Homoglyph Confusion
Attackers often use lookalike Cyrillic or Greek characters to create phishing domains that visually mimic legitimate brands (e.g. apple.com vs аpple.com).
ACE Prefix Missing
Punycode labels in DNS always begin with the four-character ASCII-Compatible Encoding prefix `xn--`.
Recommended remediation
Use ASCII-compatible encoding (xn--) when registering domains with non-standard Unicode characters in DNS zone files.
FAQ
Is Punycode / IDN Domain Converter free to use?
Yes. This tool is free and can be used without account registration.
Do you store submitted values?
Only the minimum processing needed for the check. For client-side tools, data stays in your browser.
How should I use these results?
Use the output as a diagnostic baseline, apply fixes in your stack, then re-run the check to confirm remediation.
Related security tools
DNS Lookup
Query DNS records (A, AAAA, MX, TXT, NS, CNAME) for any domain using public DNS API.
WHOIS Lookup
Retrieve domain registration details including registrar, registrant, creation date, and expiry.
URL Encoder / Decoder
Encode and decode URLs with percent-encoding. Component mode for query params. 100% client-side.
Homoglyph / IDN Checker
Detect homograph attacks — Cyrillic/Greek lookalikes in domains. Phishing prevention. 100% client-side.
Run a full security check
After this tool passes, run related header and policy checks to catch transport and browser-level risks.