Punycode & Homograph Attack Radar
Interactive RFC 3492 Punycode converter and Unicode security inspector. Detect mixed-script homograph attacks, inspect character codepoints across Cyrillic, Greek, and Latin scripts, and explore emoji domain support under IDNA2008.
Evaluating input string for homograph attack vectors and mixed script anomalies.
Standard ASCII character used in traditional Western domain names. Recognized across all English-language brand domains.
Visually indistinguishable from Latin 'a' in almost every modern font. When substituted into "paypal.com",
it encodes to xn--pypal-4ve.com in DNS wire format.
To protect users, modern browsers (Chrome, Firefox, Safari) implement Google/Mozilla IDN Display Policies. If a domain mixes Latin characters with Cyrillic, the browser forces the display of raw Punycode in the address bar.
| Top-Level Domain | Jurisdiction / Category | Emoji Support Level | Technical Implementation Notes |
|---|---|---|---|
| .ws | Samoa | Full Support | First commercial registry to officially promote single and multi-emoji domains. |
| .to | Tonga | Full Support | Widely used for creative short domains and single emoji URLs. |
| .st | São Tomé and Príncipe | Full Support | Permits emoji labels via IDNA2003 compatible nameservers. |
| .la | Laos | Supported | Marketed as Los Angeles domain, allows emoji registrations. |
| .fm | Federated States of Micronesia | Supported | Popular with audio streaming platforms, permits emoji second-level labels. |
| .com / .net | ICANN gTLDs | Strictly Prohibited | Forbidden under IDNA2008 (RFC 5890-5894). Disallowed codepoints cannot enter the zone. |