WebTools

307 Useful Tools & Utilities to make life easier.

IDN/Punycode Phishing Detector

Identify domain homograph attacks using Punycode and Unicode characters.

Paste the suspicious domain here to reveal its true Unicode form.
Analysis Results
Decoded Unicode Domain (Visual Representation)

Tip: Always check the address bar in your browser. Most modern browsers will display the xn-- version if the domain is considered suspicious.

Free Online IDN Punycode Detector: Homograph Attacks Are Spotted Before a Link Is Clicked

An email arrives with a link to https://раураӏ.com. At a glance, it looks like paypal.com. But the ‘а’ characters are Cyrillic, not Latin, and the domain is a Punycode‑encoded homograph attack designed to steal credentials. The idn homograph attack checker on this page is the tool by which any domain or URL is analyzed for mixed‑script characters, decoded from Punycode, and flagged if it contains suspicious combinations that could be used for spoofing. The analysis is performed entirely within the browser; the URL is never sent to a server. It is a vital punycode detector for security‑conscious users.

Why Punycode Detection Is Critical

Internationalized Domain Names (IDNs) use Punycode to represent Unicode characters in ASCII for DNS. While this enables a multilingual web, it also creates the opportunity for homograph attacks: domains that look identical to a trusted brand but use characters from different scripts. A detect homograph domains tool reveals the true Punycode and highlights the mixed scripts, showing that раураӏ.com is actually xn--80ak6aa92e.com. An idn spoofing checker that performs this detection before a user clicks a link can prevent credential theft and malware infections.

How the IDN Punycode Detector Is Operated

A URL or domain is pasted into the input field. The tool extracts the hostname and checks if it contains any non‑ASCII characters or begins with xn--. If it does, the domain is decoded to its full Unicode form. The tool then analyzes the character scripts: if a domain contains letters from more than one script that are visually similar—such as Latin ‘a’ (U+0061) and Cyrillic ‘а’ (U+0430)—it is flagged as a potential homograph attack. The visual similarity is checked against a database of known confusable characters (Unicode confusables). The Punycode form, the Unicode form, and a risk assessment are displayed. A green, yellow, or red indicator gives an immediate verdict.

Key Features That Are Delivered by This Detector

  • Punycode to Unicode Decoding: Any xn-- domain is instantly decoded to its Unicode equivalent.
  • Mixed‑Script Detection: The tool identifies the scripts used and flags any combination of Latin with Cyrillic, Greek, or other visually similar scripts.
  • Confusables Database: Known homoglyphs are checked, and specific spoofing patterns are recognized.
  • Risk Scoring: A risk level (Low, Medium, High) is assigned, with an explanation.
  • Privacy‑First Analysis: The URL is never sent to a server; all processing is client‑side.
  • Offline Capability: The confusables database is cached; the tool works offline.
  • Integration with Other Tools: The decoded URL can be encoded safely by the URL encoder. A hash of the domain can be generated by the SHA hash generator. Timestamps of the check are provided by the timestamp converter. SQL queries storing suspicious domains are formatted by the SQL beautifier. Patterns to extract xn-- domains from logs are tested with the regex tester. The SSL certificate of the suspect domain can be verified by the SSL checker. And the security headers of the site can be audited by the security headers checker.

Everyday Scenarios for the IDN Punycode Detector

  • Phishing Email Triage: A suspicious link is pasted, and the detector reveals it is a homograph attack. The email is reported and deleted.
  • Security Operations: A SIEM alert fires for a user clicking an IDN domain. The analyst uses the detector to confirm the domain is malicious.
  • Domain Name Purchase: A company checks a proposed domain name for potential homograph conflicts before registration.
  • Education: A security trainer shows the class how apple.com can be spoofed with Cyrillic characters, and the detector highlights the difference.
  • Browser Extension Development: A developer verifies their anti‑phishing logic by testing it against known homograph domains.


Contact

Missing something?

Feel free to request missing tools or give some feedback using our contact form.

Contact Us