การเข้ารหัส
Punycode encode/decode
เข้ารหัสชื่อโดเมนที่มีอักขระ Unicode (IDN) เป็นรูปแบบ Punycode ที่รองรับ ASCII (xn--) และย้อนกลับ
The DNS system historically only supports ASCII characters, so domain names with Cyrillic, CJK, or other non-ASCII characters (IDN) are encoded as Punycode — an ASCII-compatible form prefixed with xn--. This tool encodes and decodes such domains.
How to use it
- Encode: enter a domain with Cyrillic or other Unicode characters (e.g. пример.рф) to get its ASCII form as xn--....
- Decode: paste a domain in xn--... form to see the original characters.
- Works on both a single domain label and a full multi-level domain name.
Common uses
- Checking what real domain is hiding behind a confusing xn--... string in an email or link.
- Registering or setting up DNS for a domain with national characters when the registrar requires an ASCII form.
- Spotting a homograph attack — a domain visually mimicking a known brand using characters from a different script.
Things to keep in mind
Visually similar characters from different scripts (like Cyrillic "а" and Latin "a") can form a domain that looks identical to a known brand — this is the basis of homograph phishing.
Not every browser shows decoded Unicode the same way: when a domain label mixes scripts, browsers often deliberately show the raw xn-- form as a warning sign.
บทความเกี่ยวกับเครื่องมือนี้: Punycode: โดเมนสากลทำงานใน DNS อย่างไร
คำถามที่พบบ่อย
Punycode ใช้ทำอะไร?
Punycode เข้ารหัสชื่อโดเมนสากลที่มีอักขระนอก ASCII (เช่น münchen.de) ให้อยู่ในรูปแบบที่ใช้ได้กับ ASCII โดยมีคำนำหน้า xn-- เนื่องจากระบบ DNS รองรับเฉพาะป้ายกำกับแบบ ASCII เท่านั้น
ทำไมควรระวังโดเมน Punycode?
Punycode เปิดช่องให้เกิดการโจมตีแบบ homograph ซึ่งใช้อักขระที่หน้าตาคล้ายกันจากตัวอักษรอื่นมาลงทะเบียนโดเมนที่ดูเหมือนโดเมนที่น่าเชื่อถือทุกประการ หากโดเมนมีคำนำหน้า xn-- ให้ถอดรหัสที่นี่เพื่อดูว่าแท้จริงสะกดว่าอะไร
ใช้ได้เฉพาะกับชื่อโดเมนเต็มเท่านั้นหรือ?
คุณสามารถเข้ารหัสหรือถอดรหัสป้ายกำกับเดียวหรือทั้งโดเมนที่มีจุดคั่นได้ — แต่ละป้ายกำกับระหว่างจุดจะถูกแปลงแยกกัน และคำนำหน้า xn-- จะถูกเพิ่มเฉพาะป้ายกำกับที่มีอักขระนอก ASCII จริง ๆ เท่านั้น
จะรู้ได้อย่างไรว่าลิงก์ใช้ Punycode?
โดเมนที่เข้ารหัสแล้วจะมีคำนำหน้า xn-- อยู่หน้าแต่ละป้ายกำกับที่มีอักขระนอก ASCII เสมอ หากเห็นโดเมนที่ขึ้นต้นด้วย xn-- ในแถบที่อยู่หรือในอีเมล นั่นคือสัญญาณของ IDN ควรตรวจสอบว่าข้อความที่แท้จริงที่ซ่อนอยู่หลังการเข้ารหัสคืออะไร
เบราว์เซอร์ทุกตัวแสดงอักขระซีริลลิกในแถบที่อยู่เหมือนกันหรือไม่?
ไม่ เบราว์เซอร์บางตัวจะแสดง Unicode ที่ถอดรหัสแล้วเฉพาะเมื่ออักขระทั้งหมดในโดเมนอยู่ในชุดตัวอักษรเดียวกัน แต่เมื่อมีการผสมชุดตัวอักษร (สัญญาณของการโจมตีแบบ homograph) จะจงใจแสดงสตริง xn-- ดิบแทนอักขระต้นฉบับ