How it works

Domain names can contain non-Latin characters, and browsers encode those into an ASCII form called punycode that begins with xn--. Scammers exploit the gap between the two. They register a domain whose displayed form looks pixel-for-pixel like a real brand domain, using letters from other alphabets that render identically to Latin ones, and the actual registered domain is an xn-- string that has nothing to do with the brand. In the email the link text and even the address bar can read as the real name, while the request resolves to the attacker's server. This rides on top of the usual VPN, software, and crypto lures, because the payload is a login page or a download and the punycode domain is just the disguise that gets you there.

The tell-tale signals

What to do

Do not judge a link by how it looks, because that is the entire weakness this abuses. Hover to reveal the real URL, or copy it into a plain-text editor where an xn-- domain cannot hide. Reach the brand by typing its real domain yourself, which for NordVPN is nordvpn.com, rather than following any link in the email. Paste the raw email into LegitSponsor, which decodes punycode and flags a lookalike host against the brand's real domain, so the disguise is measured rather than eyeballed. Never enter credentials or download anything from a link you did not type yourself.