Punycode Converter (Internationalized Domain Names)

Convert internationalized domain names (IDN) containing non-ASCII characters, such as Japanese, to and from Punycode (an ASCII-compatible encoding).

What Punycode is for

The DNS has historically handled only ASCII. Yet people wanted domain names containing **characters such as kanji and kana**, as in 日本語.jp, and Punycode (RFC 3492) was devised as the bridge. It converts a Unicode string reversibly into an ASCII string beginning `xn--`, delivering internationalised domain names while leaving the existing DNS untouched.

That the result is unreadable to a human is the design working as intended: 日本語.jp becomes `xn--wgv71a119e.jp`. **Browsers hide the converted form and show the original characters in the address bar**, so it normally goes unnoticed. That gap in appearance, however, **is also a weakness open to abuse in phishing**: fake domains built from indistinguishable characters, such as Cyrillic "а" against Latin "a", have caused real trouble. This tool converts in both directions, and **everything runs in your browser.**

How to convert

  1. Choose the direction Select domain name to Punycode, or Punycode to domain name.
  2. Enter the domain name Enter it in full including the top-level domain, as in 日本語.jp.
  3. Read the result You get the converted string beginning `xn--`, or the original characters.
  4. Compare the two The ASCII form lets you check **whether any deceptive characters have crept in.**

Tips for getting more out of it

  • A domain name made up of multiple labels (parts separated by `.`) is automatically handled label by label: labels containing only ASCII characters are left unchanged, and only labels with non-ASCII characters are converted to the `xn--`-prefixed form.
  • In "Punycode → Domain Name" mode, only labels that include the `xn--` prefix are decoded; other labels are passed through unchanged.
  • The same conversion logic applies not only to domain names but also to the part after the `@` in an email address (the domain part).
  • When you actually type an internationalized domain name into a browser's address bar, most browsers convert it to Punycode internally before performing DNS resolution.

Where this helps

Registering or configuring an internationalised domain

DNS zone files and server certificates sometimes require the Punycode form.

Checking the sender of an email

**A display name that looks legitimate can turn out, once converted, to be an entirely different domain.** Such cases are real.

Reading an xn-- string in a log

Find out what an `xn--` string appearing in access logs or reports actually refers to.

Validating a configuration file

Useful for checking whether an internationalised name may be written as it stands in nginx or Apache configuration.

Punycode terms explained

Punycode
The scheme converting a Unicode string reversibly into ASCII (RFC 3492). **The result always begins `xn--`.**
Internationalised domain name
A domain name containing characters outside ASCII. Internally it is converted to Punycode to pass through the DNS.
xn--
The prefix marking a label as Punycode-encoded. It is known as the ACE prefix.
Label
Each element of a domain name separated by dots. **Conversion is performed label by label.**
Homograph attack
Building a counterfeit domain from characters that look alike. **Converting to the Punycode form exposes it.**
IDNA
The set of specifications for handling internationalised names in the DNS. IDNA2008 (from RFC 5890 onwards) is the version in use.

Frequently Asked Questions

Punycode (RFC 3492) is an encoding scheme that converts domain names containing Unicode characters — Japanese, Chinese, Arabic, and more — known as internationalized domain names (IDN), into strings made up only of the ASCII characters that DNS can handle. The converted label is given an `xn--` prefix.

DNS (the Domain Name System) was originally designed on the assumption that only ASCII characters would be used, so domain names containing Japanese characters or emoji cannot be resolved as-is. Punycode converts domain names with non-ASCII characters into ASCII strings, making internationalized domain names possible without changing the existing DNS infrastructure at all.

`xn--` is known as the "ACE prefix" (ASCII Compatible Encoding prefix), and it signals to DNS and supporting software that the label is an internationalized domain name encoded in Punycode. When browsers detect this prefix, they typically decode it back to the original Unicode string for display to the user.

Yes — this is a known phishing technique called an "IDN homograph attack." There have been reported cases where a Punycode domain (e.g. `xn--80ak6aa92e.com`) encoded using characters that look almost identical to legitimate ones — such as the Cyrillic "а" versus the Latin "a" — was used to impersonate a genuine domain. Major browsers mitigate this by displaying the raw Punycode form (the string starting with `xn--`) in the address bar instead of the decoded Unicode when they detect a suspicious mix of characters.
Tool-kun

Side Note — Behind the Scenes of How "Cat" and "日本語" Became Domain Names

Discussion of internationalized domain names (IDN) began in the late 1990s, but standardization took a long time. Several approaches were proposed for handling non-ASCII characters without changing the core of DNS, and ultimately the Punycode approach — encoding and decoding at the application layer (the client side) while leaving the DNS server itself untouched — was adopted and standardized as RFC 3492 in 2003.

The name "Punycode" is said to come from a blend of "Unicode" and "an amusing pun," and the algorithm itself is a specialization, tailored for domain names, of a more general encoding method called Bootstring (a general-purpose technique devised by IBM researchers for encoding an arbitrary character set into a restricted character set). The fact that even the origin of the name "Punycode" is something of an inside joke reflects the kind of humor typical of the developer community.

Today, domain names using a wide variety of languages and symbols — Japanese domains (`.jp`) and even emoji domains (real examples like `💩.la` exist) — are actually registered and in use, but behind the scenes this Punycode conversion process always takes place. Even the elegant Japanese domain name shown in a browser's address bar is exchanged with the DNS server as a plain ASCII string starting with `xn--`.