Phishing defense

How to spot a fake login page before you type

A fake login page copies the appearance of a real service so it can steal a password, verification code, or recovery secret. Visual design is weak evidence because attackers can copy colors, words, and screenshots. The most reliable everyday check is the destination domain combined with how you reached it.

Last reviewed: 2026-08-17 · Report a change

Read the domain from right to left

The registered domain is the meaningful part immediately before the top-level suffix such as .com. In accounts.example.com, the registered domain is example.com. In example.security-check.com, the registered domain is security-check.com, not example. Attackers add brand words to subdomains, paths, and hyphenated lookalikes.

Watch for swapped letters, added words, unusual endings, and deceptive international characters. On a phone, tap the address bar to reveal the full host. If the domain is unfamiliar, close the page and reach the service from a bookmark or a verified guide.

A padlock is not proof of legitimacy

HTTPS protects the connection between the browser and the site. It does not prove that the site belongs to the brand shown on the page. Attackers can obtain valid certificates for domains they control, so a padlock can appear on a polished phishing page.

Use HTTPS as a basic requirement, then verify the domain. Browser warnings about a certificate or unsafe site are strong reasons to stop, but the absence of a warning does not mean the page is authentic.

Be suspicious of the route, not just the page

Unexpected email, direct-message, ad, QR code, document share, calendar invite, and search result links are common delivery routes. Urgency is a warning sign: account locked, payment failed, copyright complaint, prize waiting, or security incident. Instead of clicking, open the service independently and inspect alerts inside the account.

Search ads and lookalike browser extensions can also send users to copies. A password manager that recognizes the real domain can help because it should not offer the saved credential on an unrelated host. Do not override that warning by copying and pasting the password.

Codes, prompts, and passkeys

A fake page may accept a password and immediately ask for a current 2FA code. The attacker can relay both to the real service. Never provide a code to a caller or chat contact. Reject any approval prompt you did not initiate and report repeated prompts.

Passkeys and FIDO security keys improve this situation because the authenticator checks the site identity. If the browser says no passkey is available on a page where you expected one, stop and re-check the domain instead of falling back automatically.

What to do after entering information

Act quickly from a clean, trusted device. Open the real service directly, change the password, sign out other sessions, review recovery details, and remove unknown authentication methods or connected apps. Change reused passwords on other sites, beginning with email and password managers.

If a verification code or recovery code was shared, replace or invalidate it. Check forwarding rules, tokens, API keys, marketplace listings, and messages appropriate to the service. Report the phishing page to the service and your browser or security team.

Practical checklist

How to put this into practice

  1. Stop before typing and reveal the full address bar.
  2. Identify the registered domain, not just a brand word in the URL.
  3. Close unexpected links and open the service from a bookmark.
  4. Refuse any request to share a code or approve an unstarted prompt.
  5. Use a password manager or passkey as an additional domain signal.
  6. After a mistake, secure the real account and revoke active access.

At a glance

Compare the options

SignalWhat it tells youWhat it does not prove
Correct registered domainYou reached the expected site identityThe account itself is uncompromised
HTTPS padlockThe connection is encryptedThe site belongs to the displayed brand
Matching logo and colorsThe page copied visual assetsThe page is authentic
Password manager fillsThe saved domain matchesEvery other page element is safe
Passkey worksAuthenticator recognizes the site identityRecovery and session security are perfect

Decision guidance

Choosing the right approach

Evaluate the event before the page. Ask why a sign-in is being requested now, whether you initiated the action, and whether the same alert appears after opening the service independently. A real-looking page reached through an unexpected invoice, document share, direct message, QR code, or search ad deserves more scrutiny than a familiar bookmark.

Read the hostname, not the decorative words around it. Attackers can place a brand name in a subdomain, path, query string, or page title while controlling the registrable domain. HTTPS protects the connection to that host; it does not prove the host belongs to the brand. A password manager refusing to fill can be a useful mismatch signal.

When doubt remains, close the page and start again from a known route. Do not test the page with a real password or throwaway verification code. If credentials were entered, change the password from the official service, revoke sessions, inspect recovery details, and replace exposed backup codes.

Operational test

Rehearse the moments when security usually fails

Start with an ordinary device change. Imagine the phone or computer used for this control is unavailable today, not after a carefully planned migration. Identify which trusted device, independent authenticator, recovery code, provider account, or administrator would restore access. Then verify that route without deleting the working method. For How to spot a fake login page before you type, the practical starting action remains: Stop before typing and reveal the full address bar. A recovery plan is only useful when the contact information is current and the required material can be reached without first unlocking the same account.

Next rehearse a suspected compromise. Do not answer the suspicious message or use its link to investigate. Open the known service independently, review recent sessions and security changes, and preserve evidence before removing anything. Rotate a reused password, revoke unfamiliar applications, and replace any exposed backup secret. If a second factor produced an unexpected prompt, deny it and assume the primary password may already be known. A strong authenticator helps prevent entry, but it does not clean up a stolen browser session, changed recovery address, malicious forwarding rule, or newly authorized application.

Finally, test the managed-account case. Workplaces, schools, families, and enterprise plans can place sign-in policy with an administrator or external identity provider instead of the service itself. Learn who can reset the control, what proof that person requires, and how an urgent request is authenticated. Never weaken the whole organization to solve one member's lockout. Record the official help route and an internal contact before a problem occurs, and separate administrative recovery from unsolicited support messages. This turns the comparison above—from Correct registered domain onward—into a maintainable choice rather than a one-time setup.

Common questions

How to spot a fake login page before you type FAQ

Can a fake site have HTTPS?

Yes. HTTPS is common and only proves the connection to that domain is encrypted.

What part of a URL matters most?

Check the exact registered domain immediately before the suffix, then verify the full host is expected.

Are search results safe?

Not automatically. Ads and manipulated results can point to lookalikes. Verify the destination domain.

Why did my password manager not fill?

The domain may not match the saved login. Treat that as a warning and inspect the address.

What should I do after sharing a code?

Secure the real account immediately, end other sessions, replace recovery methods, and review activity.

Apply the idea

Representative service guides

Primary guidance

Sources and further reading

Product interfaces and available methods change. Re-check each service's official help before changing a security setting, and prepare recovery before removing an older authenticator.