How to identify a phishing page
Visual and technical signs that a web page is impersonating a legitimate service to steal your credentials.
By AlertaSpam Security Team. Published August 7, 2026
Phishing pages are built to survive a quick glance — the layout and logo are usually a close copy of the real site. What they can't easily fake is the domain itself, so that's always where to look first, before judging anything about how the page looks.
Warning signs
- The domain — the text right after 'https://' and before the first single '/' — doesn't match the real organization character for character.
- A generic greeting ('Dear customer') instead of your name, where the real service normally greets you by name.
- An urgency banner ('verify now or your account will be closed') paired with a login form shown before any other content loads.
- A padlock icon in the address bar — this only means the connection is encrypted, not who owns the site. Most phishing pages use HTTPS too.
- A logo that's slightly the wrong size, color, or resolution compared to the real one.
Step-by-step
- Look at the address bar before anything else on the page.
- Compare the domain to the real organization's domain, letter by letter — watch for a swapped letter, an added hyphen, or an extra word ('yourbank-secure.com' instead of 'yourbank.com').
- Hover over any link on the page (without clicking) to preview where it actually leads.
- If you're unsure, look the domain up on AlertaSpam instead of interacting with the page further.
- If you need the real service, type its address yourself or use a bookmark you already trust — never continue through the link that got you here.
Examples of look-alike domains
- 'yourbank-secure-login.com' instead of 'yourbank.com'
- 'yourbank.account-verify.example.com' (the real domain here is 'example.com', not 'yourbank.com')
- 'y0urbank.com' (a zero standing in for the letter O)
What not to do
- Don't judge a page as legitimate because it looks professional — cloned phishing kits can copy a real site pixel for pixel.
- Don't type your password 'just to see what happens' — assume the first field you touch is being captured.
- Don't trust a link just because it arrived from a contact you know; their account may itself be compromised.
Frequently asked questions
The site has a padlock and 'https' — doesn't that mean it's safe?
No. HTTPS only encrypts the connection between you and whatever server the domain points to — it says nothing about who controls that domain. The vast majority of phishing pages today use HTTPS.
What if the page is an exact pixel-for-pixel copy of the real one?
That's expected — copying the design is the easy part for an attacker. The domain is the one thing that's genuinely hard to fake, which is why it's the first and most reliable thing to check.
