//
No customization controls needed for this tool. It transforms text automatically!
Supports text inputs up to 50 MB. Computations execute entirely within your local browser memory with zero server uploads.
google.com (with Cyrillic 'о' U+043E) looks completely legitimate, but leads to a malicious phishing server. The Homoglyph Security Detector & IDN Punycode Analyzer inspects text and URLs in real time. It highlights mixed-script anomalies, identifies disguised Unicode code points, detects invisible zero-width characters, and converts IDNs to ASCII Punycode (xn--...) to prevent phishing and spoofing vulnerabilities.The Unicode standard contains over 149,000 characters spanning dozens of global scripts. Many characters in separate alphabets share identical or indistinguishable visual glyphs:
U+0430) is visually identical to Latin 'a' (U+0061). Similarly, Cyrillic 'о' (U+043E), 'е' (U+0435), 'р' (U+0440), and 'с' (U+0441) mimic Latin o, e, p, c.U+03BF) mimics Latin 'o'.U+200B), Zero-Width Non-Joiner (U+200C), and Right-to-Left marks (U+200F) can be injected into passwords, code, or usernames to bypass security filters or cause invisible payload execution.xn--). Our detector decodes and highlights the exact non-Latin code points.U+0430), script family, and ASCII lookalike.xn-- domain representation.U+200B), ZWJ, ZWNJ, and RTL overrides.xn--...) for domain security auditing.Scenario: Analyzing a spoofed login domain using Cyrillic 'о'.
https://gооgle.com/login (containing Cyrillic U+043E)
Threat Level: HIGH RISK 🚨 | Detected Homoglyphs: 2x Cyrillic 'о' (U+043E) | Punycode: xn--ggle-p50aa.com
Unmasks a deceptive phishing URL targeting Google users.
Scenario: Scanning a source code snippet for invisible Trojan characters.
const adminUser = true;
Detected: 1 Invisible Zero-Width Space (U+200B) at index 11
Alerts developers to hidden invisible characters that alter variable definitions.