From: "https://mail.google.com"
If they looked the same.
Because the #1 use case for this isn’t emoji, but sites such as bücher.de (I originally had a link here to the site, but HN punycodes that: http://xn--bcher-kva.de/ ) (which nowadays had to redirect, because the URL displayed in punycode made people believe it was a phishing attempt)
network.IDN_show_punycode = true
URLs are no place for unicode characters to hide in. An xn-- prefix is all the warning you need.https://wiki.mozilla.org/IDN_Display_Algorithm
Much better than showing punycode all the time.
That’s a very america-centric world, it’s like enforcing only US-ASCII on all websites. Most of the world doesn’t speak English, and browsers showing domains punycoded leads to mistrust, especially if it’s a legitimate retailer (the one mentioned above actually added a redirect to a romanized version of the URL due to that)
[0] https://wiki.mozilla.org/IDN_Display_Algorithm#Algorithm
[1] https://www.chromium.org/developers/design-documents/idn-in-...
In the end, you would just highlight nearly everything. A more useful approach would be to highlight when you switch script inside a domain name. That seems to be what firefox does for non-whitelisted domains (with some more rules to allow eg www.stマイクロ.jp (ST Microelectronics in japanese))