{"success":true,"data":{"id":"href-punycode-host","label":"Punycode host in link — URL-level homograph attack (xn-- decodes to a spoofed brand)","description":"An `<a href>` in the body points at a hostname containing an `xn--` label — the ASCII encoding of a non-ASCII internationalized domain name. A link to `https://xn--pple-43d.com/login` decodes to \"ápple.com\" which a sighted user glancing at a rendered button sees as \"apple.com\". Legitimate English-language brands register the plain ASCII form and link to that; local-script brands link to the decoded-Unicode form their audience renders correctly. Raw `xn--` in an email href is attack-shaped — the URL-level sibling of the sender-level `punycode-domain` signal.","tier":"danger","category":"other","isThin":false}}