How to spot a fake login page
A fake login page is a copy of a real sign-in screen built to steal the username and password you type into it.
How a fake login page works
Scammers copy a familiar sign-in screen: your bank, your email, a shop. The logo, the colors, and the layout can be a perfect match. The trick is not how the page looks but where it sends what you type.
Check the web address first
A design can be faked. The domain is much harder. Read it from the end backward.
- The main domain is the part right before the first single slash: google.com, not goggle-login.com or account-secure.net.
- Watch for swapped letters: paypa1.com uses a one for the L, micros0ft.com a zero.
- Extra words glued to a brand: secure-appleid-login.com is not apple.com.
- A raw address of numbers, like 185.42.10.9, or a long chain of dots before the real name.
Watch how the page behaves
- You did not go looking for it. A login screen that appears from an unexpected link deserves a second look.
- It asks for too much: a full card number, a PIN, or a recovery phrase alongside the password.
- It shows a code to approve or read out to someone: a device-code scam.
- It pressures you with countdown timers and threats about losing access, so you will not check the address.
How to protect yourself
- Do not sign in from links in messages. Open a new tab and type the address, or use a bookmark.
- A password manager fills your password only on the exact site it was saved for, so its silence on a page that looks right is a warning.
- Turn on two-step verification. Even if a password leaks, the second step blocks most sign-ins.
- If you are unsure, stop. Close the tab and contact the company through a number you already trust.
Fish Catcher warns you in plain language when a login screen sits on a lookalike domain or a site it does not recognize. It never blocks the page.
Common questions
The page looks exactly like the real one. Does that mean it is safe?
No. Looks are the easiest part to copy. A scammer can save the real page and change only where your password goes.
There is a padlock in the address bar. Is that enough?
No. The padlock means the connection is encrypted. It says nothing about who owns the site, and many phishing pages have one.
I already typed my password into a page I now think was fake. What should I do?
Change that password right away on the real site, opened by typing the address yourself, and on any other site where you reused it.