🌍 Punycode / IDN Converter
Convert an internationalized domain name (with accents, non-Latin scripts, etc.) to its
ASCII-compatible Punycode form (the xn-- encoding browsers and DNS use), or decode
a Punycode domain back to Unicode.
How the encoding works
The full RFC 3492 Punycode algorithm runs in your browser - nothing is sent
anywhere. The domain is split on dots and each label is handled on its own.
Direction is picked automatically: if any label starts with xn-- the
input is decoded, otherwise it is encoded. Pure ASCII labels such as
de and com pass through untouched.
Encoding keeps the ASCII characters in place, adds a hyphen, then appends a compressed description of which non-ASCII characters were removed and where they belonged:
münchen.de -> xn--mnchen-3ya.de ( munchen minus the u-umlaut, plus 3ya )
bücher.de -> xn--bcher-kva.de
café.fr -> xn--caf-dma.fr
日本.jp -> xn--wgv71a.jp ( no ASCII at all, so no hyphen before it )
Where you need each form
DNS itself only carries ASCII, so the xn-- form is what goes in your
zone file, your TLS certificate, your SPF and DMARC records and any redirect
rules. The Unicode form is only a display convenience, which browsers render when
they judge it safe. Register the name and the registry stores the ASCII form; type
the accented name and the browser converts before it asks any resolver.
xn-- string when a label
mixes scripts, because Cyrillic а and Latin a are visually identical. That is
an anti-spoofing measure, not a fault in your domain.Frequently asked questions
What does xn-- mean at the start of a domain?
It is the ASCII Compatible Encoding prefix. It marks a label as Punycode, so resolvers and browsers know the rest of the label decodes to non-ASCII characters rather than being read literally.
Do I put the Unicode or the Punycode form in my DNS records?
Punycode. Zone files, certificates and mail records all need the
xn-- form. Some control panels convert for you, but the value
actually stored is always ASCII.
Why does my browser show xn-- instead of the accented name?
Because the label failed the browser's script-mixing check. Names combining characters from different alphabets can imitate a well-known domain, so the browser falls back to the unambiguous ASCII form.