How to spot a fake login page
A fake login page is a copy of a real sign-in screen built to steal the username and password you type into it.
How a fake login page works
Scammers copy a familiar sign-in screen. It might look like your bank, your email, or a shopping account. The page can be a near-perfect match. The logo, the colors, and the layout can all look correct.
The trick is not in how the page looks. It is in where the page lives and what it does with what you type. A real login sends your password to the company that owns the account. A fake one sends it to a stranger. That stranger then signs in as you, often within minutes.
You usually reach these pages through a link. The link arrives in an email, a text message, an ad, or a search result. The message tries to rush you. It says your account is locked, a payment failed, or a package is stuck. The goal is to make you act before you look.
Check the web address first
The address bar is the most reliable place to look. The design of a page can be faked. The real domain is much harder to fake. Read the address slowly, from the end of the site name backward.
- Look at the main domain, the part right before the first single slash. For a real Google sign-in that part is google.com. If it reads goggle-login.com or account-secure.net, it is not Google.
- Watch for small misspellings and swapped letters. paypa1.com uses the number one in place of the letter L. micros0ft.com uses a zero. These are easy to miss at a glance.
- Be careful with extra words glued to a brand name. secure-appleid-login.com is not apple.com. The real brand is a full domain, not a word buried in a longer address.
- Do not trust the padlock alone. A padlock means the connection is encrypted. It does not mean the site is honest. Many phishing pages have a padlock.
- Be wary of a raw address made of numbers, like 185.42.10.9, or a very long chain of dots before the real name. Real companies rarely ask you to sign in at an address like that.
Watch how the page behaves
The page itself can give warnings if you slow down and notice them.
- You did not go looking for it. A login screen that pops up from a link you did not expect deserves a second look.
- It asks for too much. A normal sign-in wants a username and a password. A fake one may also ask for your full card number, a PIN, or your recovery phrase. Legitimate sign-in pages do not ask for those together.
- The page shows a code and asks you to approve it, or asks you to read a code out to someone. This is a device-code scam. Approving that code can hand your account to an attacker.
- It pressures you. Countdown timers and threats about losing access are there to stop you from checking the address.
- Links go nowhere. On a fake page, the help, privacy, and contact links are often dead or point to odd addresses.
How to protect yourself
A few steady habits close off most of these attacks.
- Do not sign in from links in messages. Open a new tab and type the address yourself, or use a bookmark you saved earlier.
- Use a password manager. It fills your password only on the exact site it was saved for. If it does not offer to fill on a page that looks right, treat that as a warning.
- Turn on two-step verification where you can. Even if a password leaks, the second step blocks most sign-in attempts.
- Never approve a sign-in code you did not start yourself, and never read one aloud to anyone.
- If you are unsure, stop. Close the tab. Contact the company through a number or address you already trust.
A tool can watch for these signals while you browse. Fish Catcher is a free, open-source browser extension that checks the page on your device and warns you in plain language when a login screen sits on a lookalike domain or on a site it does not recognize. It shows a simple color, from green for no suspicious signs up to red for strong signs of a fake. It never blocks the page. You stay in control and decide what to do next.
Common questions
The page looks exactly like the real one. Does that mean it is safe?
No. Looks are the easiest part to copy. A scammer can save the real page and change only where your password is sent. Judge the web address and the behavior, not the design.
There is a padlock in the address bar. Is that enough?
No. The padlock only means the connection is encrypted so others cannot read it in transit. It says nothing about who owns the site. Many phishing pages have a valid padlock.
I already typed my password into a page I now think was fake. What should I do?
Change that password right away, on the real site, opened by typing the address yourself. If you reused that password elsewhere, change it there too. Turn on two-step verification, then watch the account for sign-ins you do not recognize.