Last reviewed: 2026-08-17 · Report a change
Try it in your browser: Check a suspicious link without opening it · Follow the complete official-login checklist
Read the domain from right to left
The registered domain is the meaningful part immediately before the top-level suffix such as .com. In accounts.example.com, the registered domain is example.com. In example.security-check.com, the registered domain is security-check.com, not example. Attackers add brand words to subdomains, paths, and hyphenated lookalikes.
Watch for swapped letters, added words, unusual endings, and deceptive international characters. On a phone, tap the address bar to reveal the full host. If the domain is unfamiliar, close the page and reach the service from a bookmark or a verified guide.
A padlock is not proof of legitimacy
HTTPS protects the connection between the browser and the site. It does not prove that the site belongs to the brand shown on the page. Attackers can obtain valid certificates for domains they control, so a padlock can appear on a polished phishing page.
Use HTTPS as a basic requirement, then verify the domain. Browser warnings about a certificate or unsafe site are strong reasons to stop, but the absence of a warning does not mean the page is authentic.
Be suspicious of the route, not just the page
Unexpected email, direct-message, ad, QR code, document share, calendar invite, and search result links are common delivery routes. Urgency is a warning sign: account locked, payment failed, copyright complaint, prize waiting, or security incident. Instead of clicking, open the service independently and inspect alerts inside the account.
Search ads and lookalike browser extensions can also send users to copies. A password manager that recognizes the real domain can help because it should not offer the saved credential on an unrelated host. Do not override that warning by copying and pasting the password.
Codes, prompts, and passkeys
A fake page may accept a password and immediately ask for a current 2FA code. The attacker can relay both to the real service. Never provide a code to a caller or chat contact. Reject any approval prompt you did not initiate and report repeated prompts.
Passkeys and FIDO security keys improve this situation because the authenticator checks the site identity. If the browser says no passkey is available on a page where you expected one, stop and re-check the domain instead of falling back automatically.
What to do after entering information
Act quickly from a clean, trusted device. Open the real service directly, change the password, sign out other sessions, review recovery details, and remove unknown authentication methods or connected apps. Change reused passwords on other sites, beginning with email and password managers.
If a verification code or recovery code was shared, replace or invalidate it. Check forwarding rules, tokens, API keys, marketplace listings, and messages appropriate to the service. Report the phishing page to the service and your browser or security team.
Practical checklist
How to put this into practice
- Stop before typing and reveal the full address bar.
- Identify the registered domain, not just a brand word in the URL.
- Close unexpected links and open the service from a bookmark.
- Refuse any request to share a code or approve an unstarted prompt.
- Use a password manager or passkey as an additional domain signal.
- After a mistake, secure the real account and revoke active access.
At a glance
Compare the options
| Signal | What it tells you | What it does not prove |
|---|---|---|
| Correct registered domain | You reached the expected site identity | The account itself is uncompromised |
| HTTPS padlock | The connection is encrypted | The site belongs to the displayed brand |
| Matching logo and colors | The page copied visual assets | The page is authentic |
| Password manager fills | The saved domain matches | Every other page element is safe |
| Passkey works | Authenticator recognizes the site identity | Recovery and session security are perfect |
Decision guidance
Choosing the right approach
Evaluate the event before the page. Ask why a sign-in is being requested now, whether you initiated the action, and whether the same alert appears after opening the service independently. A real-looking page reached through an unexpected invoice, document share, direct message, QR code, or search ad deserves more scrutiny than a familiar bookmark.
Read the hostname, not the decorative words around it. Attackers can place a brand name in a subdomain, path, query string, or page title while controlling the registrable domain. HTTPS protects the connection to that host; it does not prove the host belongs to the brand. A password manager refusing to fill can be a useful mismatch signal.
When doubt remains, close the page and start again from a known route. Do not test the page with a real password or throwaway verification code. If credentials were entered, change the password from the official service, revoke sessions, inspect recovery details, and replace exposed backup codes.
Operational test
Rehearse the moments when security usually fails
Start with an ordinary device change. Imagine the phone or computer used for this control is unavailable today, not after a carefully planned migration. Identify which trusted device, independent authenticator, recovery code, provider account, or administrator would restore access. Then verify that route without deleting the working method. For How to spot a fake login page before you type, the practical starting action remains: Stop before typing and reveal the full address bar. A recovery plan is only useful when the contact information is current and the required material can be reached without first unlocking the same account.
Next rehearse a suspected compromise. Do not answer the suspicious message or use its link to investigate. Open the known service independently, review recent sessions and security changes, and preserve evidence before removing anything. Rotate a reused password, revoke unfamiliar applications, and replace any exposed backup secret. If a second factor produced an unexpected prompt, deny it and assume the primary password may already be known. A strong authenticator helps prevent entry, but it does not clean up a stolen browser session, changed recovery address, malicious forwarding rule, or newly authorized application.
Finally, test the managed-account case. Workplaces, schools, families, and enterprise plans can place sign-in policy with an administrator or external identity provider instead of the service itself. Learn who can reset the control, what proof that person requires, and how an urgent request is authenticated. Never weaken the whole organization to solve one member's lockout. Record the official help route and an internal contact before a problem occurs, and separate administrative recovery from unsolicited support messages. This turns the comparison above—from Correct registered domain onward—into a maintainable choice rather than a one-time setup.
Common questions
How to spot a fake login page before you type FAQ
Can a fake site have HTTPS?
Yes. HTTPS is common and only proves the connection to that domain is encrypted.
What part of a URL matters most?
Check the exact registered domain immediately before the suffix, then verify the full host is expected.
Are search results safe?
Not automatically. Ads and manipulated results can point to lookalikes. Verify the destination domain.
Why did my password manager not fill?
The domain may not match the saved login. Treat that as a warning and inspect the address.
What should I do after sharing a code?
Secure the real account immediately, end other sessions, replace recovery methods, and review activity.
Apply the idea
Representative service guides
Primary guidance
Sources and further reading
Product interfaces and available methods change. Re-check each service's official help before changing a security setting, and prepare recovery before removing an older authenticator.