Domains, emails or URLs
Convert internationalized domain names (IDN) between their Unicode form, such as ñandú.com.ar, and the ASCII Punycode form used by DNS, such as xn--and-6ma2c.com.ar. The direction is detected automatically, full email addresses and URLs are accepted, and you are warned when a domain mixes scripts to impersonate another one.
Up to 500 lines. For emails only the domain is converted, and for URLs only the host.
Result
Unicode → ASCII
Unicodeñandú.com.ar
ASCIIxn--and-6ma2c.com.ar
ñandúxn--and-6ma2c13 · Latin
ASCII → Unicode
Unicodemünchen.de
ASCIIxn--mnchen-3ya.de
münchenxn--mnchen-3ya14 · Latin
Unicode → ASCIIEmail
Unicodecontacto@correo.españa.es
ASCIIcontacto@correo.xn--espaa-rta.es
españaxn--espaa-rta13 · Latin
Unicode → ASCIIURL
Unicodehttps://日本語.jp/ページ
ASCIIhttps://xn--wgv71a119e.jp/%E3%83%9A%E3%83%BC%E3%82%B8
日本語xn--wgv71a119e14 · Han
Unicode → ASCII
Unicodeаррӏе.com
ASCIIxn--80ak6aa92e.com
аррӏеxn--80ak6aa92e14 · Cyrillic

The label is written entirely with Cyrillic or Greek letters that look identical to Latin letters. It may be impersonating a well-known domain: check the xn-- form before trusting the link.

Punycode without prefix (RFC 3492)

Encode or decode any text with the plain Punycode algorithm, without the xn-- prefix or domain normalization. Useful for debugging your own implementation.

Resultmaana-pta

How it works

DNS only accepts ASCII letters, digits and hyphens, so a domain like ñandú.com.ar cannot travel as is. Internationalized domain names (IDN) solve this with Punycode (RFC 3492): each label containing non-ASCII characters is encoded with an algorithm that keeps the basic letters and appends the positions of the special ones at the end, and the xn-- prefix is added in front. That is how ñandú becomes xn--and-6ma2c.

Before encoding, IDNA normalizes the name: it lowercases it, unifies Unicode forms and converts alternative dots such as the Japanese 。. This tool uses the same mapping (UTS #46) that browsers apply when opening an address, so the result matches what is eventually sent to DNS. For emails it converts only the domain, and for URLs only the host.

It also breaks down each label with its length and the scripts it uses, and warns when a domain mixes alphabets or is written with Cyrillic or Greek letters identical to Latin ones: this is the basis of homograph attacks, in which a link appears to belong to a well-known site.

Examples

ñandú.com.arxn--and-6ma2c.com.arOnly the label with special characters changes; com and ar stay the same. This is the form you must enter in DNS and in the SANs of a certificate.
faß.dexn--fa-hia.deUnder IDNA2008 the German ß is a valid letter and gets encoded. Under the previous standard it was converted to ss and pointed to fass.de, a different domain: that is why some older systems resolve something else.
аррӏе.comxn--80ak6aa92e.comThe homograph published by Xudong Zheng in 2017: five Cyrillic letters that look exactly like apple. Since then Chrome and Firefox display this kind of domain in its xn-- form.
пример.рфxn--e1afmkfd.xn--p1aiTop-level domains can be internationalized too: .рф is Russia's Cyrillic TLD, written as xn--p1ai in DNS.

Use cases

  • Get the xn-- form of a domain with accents or special characters to create DNS records, configure nginx or Apache, or fill in the SANs of a certificate.
  • Understand which real domain lies behind an xn-- that shows up in a log, a phishing report or the browser's address bar.
  • Inspect a suspicious link to detect Cyrillic or Greek letters that imitate Latin ones.
  • Convert the domain of an internationalized email address for a server that does not support SMTPUTF8.
  • Check that an international domain does not exceed 63 characters per label once encoded.

Frequently asked questions

What does the xn-- prefix mean?

It is the ACE (ASCII Compatible Encoding) prefix, which marks the label as Punycode. Labels with hyphens in the third and fourth positions are reserved for these prefixes, so registries do not allow a domain starting with xn-- unless it is a valid IDN.

Which form should I use in DNS, on the web server and in the certificate?

The ASCII form, with xn--, in every technical place: DNS records, nginx server_name, Apache ServerName, certificate SANs and Host headers. The Unicode form is only for displaying to people; browsers convert it before making the request.

What is a homograph attack?

It means registering a domain that looks identical to another one by using letters from a different alphabet, such as the Cyrillic a instead of the Latin one. Browsers show the xn-- form when a label mixes scripts or resembles a well-known domain. If a link looks normal but its ASCII form starts with xn--, be suspicious.

Can an email address contain accents?

The domain can, and it can be converted to xn-- for any server. The part before the @ is a different story: with non-ASCII characters it requires every server along the way to support SMTPUTF8 (RFC 6531), and it has no equivalent Punycode form.

Why did my domain with uppercase letters change?

Domain names are case-insensitive, and IDNA lowercases everything before encoding: MÜNCHEN.de and münchen.de are the same domain, xn--mnchen-3ya.de. Plain Punycode does preserve uppercase, which is why the converter without prefix gives different results.