How to spot a fake login page

Updated View source
Stay safe

A fake login page is a copy of a real sign-in screen built to steal the username and password you type into it.

How a fake login page works

Scammers copy a familiar sign-in screen. It might look like your bank, your email, or a shopping account. The page can be a near-perfect match. The logo, the colors, and the layout can all look correct.

The trick is not in how the page looks. It is in where the page lives and what it does with what you type. A real login sends your password to the company that owns the account. A fake one sends it to a stranger. That stranger then signs in as you, often within minutes.

You usually reach these pages through a link. The link arrives in an email, a text message, an ad, or a search result. The message tries to rush you. It says your account is locked, a payment failed, or a package is stuck. The goal is to make you act before you look.

Check the web address first

The address bar is the most reliable place to look. The design of a page can be faked. The real domain is much harder to fake. Read the address slowly, from the end of the site name backward.

Watch how the page behaves

The page itself can give warnings if you slow down and notice them.

How to protect yourself

A few steady habits close off most of these attacks.

A tool can watch for these signals while you browse. Fish Catcher is a free, open-source browser extension that checks the page on your device and warns you in plain language when a login screen sits on a lookalike domain or on a site it does not recognize. It shows a simple color, from green for no suspicious signs up to red for strong signs of a fake. It never blocks the page. You stay in control and decide what to do next.

Common questions

The page looks exactly like the real one. Does that mean it is safe?

No. Looks are the easiest part to copy. A scammer can save the real page and change only where your password is sent. Judge the web address and the behavior, not the design.

There is a padlock in the address bar. Is that enough?

No. The padlock only means the connection is encrypted so others cannot read it in transit. It says nothing about who owns the site. Many phishing pages have a valid padlock.

I already typed my password into a page I now think was fake. What should I do?

Change that password right away, on the real site, opened by typing the address yourself. If you reused that password elsewhere, change it there too. Turn on two-step verification, then watch the account for sign-ins you do not recognize.