Definition · DNS & Email Spoofing

What is Internationalised Domain Name?

An internationalised domain name is a domain containing characters that classic DNS cannot carry directly — accented Latin letters, Greek, Cyrillic, Arabic, Han characters and so on. IDNs exist so that people can use domains in their own writing systems, including entire top-level domains such as .рф and .中国.

Nothing in the DNS protocol changed to support them. Instead, the application performs the conversion: it normalises the Unicode input under the IDNA framework, then encodes each non-ASCII label with Punycode and prefixes it with xn--. What the resolver sees is ordinary ASCII. What the user typed, and what they are shown, is Unicode. The gap between those two representations is where the security problems live.

Two forms of one name

  • U-label — the Unicode form, for display: société.example
  • A-label — the ASCII form, for the wire: xn--socit-esab.example

The current framework, IDNA2008, replaced the earlier IDNA2003 rules and changed how some characters are handled, so an older library and a newer one can map the same input to different A-labels. Anything comparing domains — allowlists, blocklists, SIEM correlation, certificate matching — should normalise to the A-label first rather than comparing rendered text.

Risks and mitigations

The headline risk is visual impersonation: a mixed-script or wholly non-Latin label can be indistinguishable from a familiar brand, which is the basis of the IDN homoglyph attack and a more convincing variant of ordinary typosquatting. Registries restrict which scripts may be combined within a label, and browsers fall back to showing the A-label when a name looks suspicious, but neither control is comprehensive across every TLD and every client.

There are also handling bugs to consider. Software that decodes for display in one place and compares raw bytes in another can be tricked into treating two different names as the same, or the same name as two different ones, which has produced real filter bypasses and certificate-matching defects over the years.

If your organisation registers IDNs legitimately — for local-language brands — record both forms in your asset inventory, since the A-label is what will appear in Certificate Transparency logs, passive DNS and WHOIS queries.

See Punycode for the encoding itself, DNS record types, and asset discovery.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.