Skip to main content

How IDN homograph attacks work and how to spot them

Internationalized domain names (IDNs) allow letters from many scripts in a domain. In a homograph attack, someone registers a domain in which Latin letters are swapped for identical-looking letters from another script, so a link looks like a trusted address but leads to a different domain.

Worked example

Input
еxаmple.com
Scripts found
Cyrillic (Cyrl), Latin (Latn)
Characters flagged
2
IndexCharacterCode pointScriptReplacementRule
0еU+0435CyrilliceConfusable map
2аU+0430CyrillicaConfusable map
Punycode (what DNS looks up)
xn--xmple-4ve7a.com
Strict ASCII Fallback
example.com

How it works

  • DNS works with ASCII only, so a label containing other characters is converted to Punycode, which starts with xn--. The Punycode form is the real name: if a familiar-looking address turns into xn--…, it is not the domain it appears to be.
  • Browsers usually display the Punycode form when a label mixes scripts, but email clients, chat apps, and documents often show the deceptive Unicode form, and a label written entirely in one look-alike script can slip through.
  • To check a domain, paste it into the detector. Any flagged character, more than one script in a label, or a cleaned form that differs from the original means you should type the address yourself or use a bookmark instead of the link.

Conversion is best-effort: mapped confusables and NFKC folding are deterministic, but some legitimate Unicode will not be flagged.

Your text

Paste or type — results update as you type (lightly debounced for long input).

11 characters scanned
2 suspicious
Strict ASCII Fallback
Conversion mode

Strict ASCII mode aggressively replaces known lookalikes with ASCII. It can change legitimate non-Latin text when a character is in the bundled map or NFKC-folded.

Original (suspicious characters marked)

Suspicious characters in the original view are underlined and labeled “susp.” in addition to highlight color.

suspicious character еxsuspicious character аmple.com
Cleaned output
Character analysis
Index (0-based)OriginalReplacementCode pointReason
0еeU+0435Non-ASCII confusable mapped to a safer Latin ASCII equivalent.
1xxU+0078Not flagged as a confusable or compatibility character.
2аaU+0430Non-ASCII confusable mapped to a safer Latin ASCII equivalent.
3mmU+006DNot flagged as a confusable or compatibility character.
4ppU+0070Not flagged as a confusable or compatibility character.
5llU+006CNot flagged as a confusable or compatibility character.
6eeU+0065Not flagged as a confusable or compatibility character.
7..U+002ENot flagged as a confusable or compatibility character.
8ccU+0063Not flagged as a confusable or compatibility character.
9ooU+006FNot flagged as a confusable or compatibility character.
10mmU+006DNot flagged as a confusable or compatibility character.

More guides