Phishing links and fake login pages

Most online scams end in the same place: a web page that looks real and asks you to log in or pay. Learning to read a web address takes two minutes and protects you from almost all of them.

In short

Learn the one skill that stops most scams: reading who really owns a link. With examples of look-alike addresses and fake login pages.

Top warning signs: The brand appears, but not as the real domain; Look-alike spelling; Extra words.

First thing to do: Don't log in from links in messages. Use the app, or type the address yourself.

Example · EmailIllustrative, links disabled
Account Security <security@paypa1-support[.]com>
We noticed unusual sign-in activity on your account. Your account has been limited. Please verify your information within 24 hours to restore full access: paypal.com.account-verify[.]info/login
An example scam message with the warning signs highlighted.

How the scam works

Phishing pages copy logos and layouts perfectly. The only part a scammer can't fake is the real domain name: the name right before the first single “/”, together with its ending (.com, .co.uk and so on).

Red flags to look for

  • The brand appears, but not as the real domain. paypal.com.account-verify.info belongs to account-verify.info. Read from the right.
  • Look-alike spelling. paypa1, arnazon, micros0ft, or special characters that look like normal letters.
  • Extra words. secure-login-, -verify, -support, -refund.
  • Shortened links. bit.ly and similar hide the destination. Our checker follows them for you.
  • Brand-new domains. Days-old websites asking for logins are almost always phishing.

What to do if you get one

  1. Don't log in from links in messages. Use the app, or type the address yourself.
  2. Paste unsure links into TapSafely. We show the real owner, age and where the link really goes.
  3. Use a password manager: it won't auto-fill your password on a fake domain, which is a great early warning.

Read a link from right to left

LinkReal ownerVerdict
https://www.amazon.co.uk/ordersamazon.co.ukGenuine domain
https://amazon.co.uk.refund-centre[.]toprefund-centre.topFake
https://login.microsoftonline.commicrosoftonline.comGenuine domain
https://micros0ft-login[.]commicros0ft-login.comFake (zero instead of o)

If you already paid or shared details

Act quickly. It makes a difference.

  1. Change the password on the real site, and anywhere else you used it.
  2. Turn on two-step verification and check account settings for new forwarding rules or devices.
  3. If you entered card details, call your bank.

More help: what to do after a scam, and where to report it in your country.

Questions people ask

Is a link safe if it starts with https?

No. https only means the connection is encrypted, not that the site is honest.

Official sources and further reading

We check our guides against advice from government agencies and consumer protection bodies.