Domain Hall of Fame / International names and look-alike letters

International names and look-alike letters

DOMAINS

3 min read · 705 words

Domain names can contain letters beyond the basic Latin alphabet: accents, Cyrillic, Greek, Chinese and more. These internationalised names are stored in DNS in an encoded form that starts with xn--, called punycode, while browsers display the readable version.

They are valuable for audiences who write in those scripts. A bakery in Munich can have münchen.example and a customer in Sofia can type an address in Cyrillic without switching keyboard layout. They also open the door to look-alikes, which is the part that matters for security.

How the encoding works

DNS itself only carries a small set of characters: letters a to z, digits and hyphens. To fit everything else into that, each label containing other characters is converted into an ASCII form with the xn-- prefix. The conversion is reversible, so a browser can show you the readable version while the network sees the encoded one.

bücher.examplewhat people read xn--bcher-kvawhat DNS stores bücher.exampleshown in the browser encode decode Certificates, DNS records and logs use the encoded form.
The readable name is a display convenience; the stored name is plain ASCII.

You can see it with one line of Python:

python3 -c "print('bücher.example'.encode('idna'))"
b'xn--bcher-kva.example'

In your DNS control panel, you will normally enter the xn-- form, or the panel will convert for you. Certificates are issued for the encoded name, and server logs record it that way, so searches for the readable form can miss them.

Look-alike letters

A Cyrillic letter that looks identical to a Latin one can make a fake address indistinguishable by eye. Many lower-case Cyrillic letters are drawn almost exactly like Latin ones, yet they are different characters with different code points, and the domain system treats them as different.

LatinCyrillicLook the same? a U+0061а U+0430near identical e U+0065е U+0435near identical o U+006Fо U+043Enear identical p U+0070р U+0440near identical x U+0078х U+0445near identical
Different characters, different code points, and in many fonts, almost the same shape.

Take example.com and swap the first three letters for Cyrillic ones, and you get a name that reads identically on screen but is stored as xn--mple-43d3a6i.com. A phishing email linking to it looks right to anyone who is not checking.

What browsers and registries do about it

Browsers have rules that show the encoded form when scripts are mixed, but they are not perfect. A name made entirely of Cyrillic letters that happen to resemble Latin ones has no mixing, so it can slip past rules that look for mixed scripts. Browsers have added further checks over the years, and the details differ by browser, so do not assume the one on your phone is as careful as the one on your desk.

Registries contribute as well. Many allow only characters appropriate to a language they list, and some bundle the variants of a name so that one owner gets the lot. Policies vary a great deal between endings.

Email and certificates

An internationalised domain behaves like any other once it is in its encoded form. A certificate covers the xn-- name, and the address bar shows the readable one if the browser considers it safe. Mail is where support is patchiest. The domain part of an address works almost everywhere, because the receiving server sees ASCII. Non-ASCII characters before the @ need support at both ends, and many systems still reject them.

If your customers use older software, such as a till system or a mailing-list tool, test with a real address before you announce one.

What to do if your brand is a target

  1. If your brand is attractive to impersonators, consider registering the obvious look-alike variants. Register the few most plausible, not every permutation: there are too many.
  2. Tell your customers to use bookmarks, or to type the address themselves instead of following links in email.
  3. Set up monitoring for newly registered names that resemble yours. Some registrars and security services offer it.
  4. Publish SPF, DKIM and DMARC at an enforcing policy so that mail pretending to be you fails checks.
  5. Know the take-down route: the registrar's abuse contact and, where it applies, the dispute procedure for the ending.

Verifying it

PreviousTrademarks: check before you fall in loveNextWhy a clever ending can be a risk

More from Domain Hall of Fame

Domains

Protect what you have

The cheapest security measures for a domain are also the most effective. Enable registrar lock, which...

Domains

What your registration data reveals

Registering a domain requires contact details: name, address, email and phone. For years these appeared in...

Domains

Renewal is the real price

Registrars compete on the first-year price and make their money on renewals. A domain that costs less than a...