Most phishing does not fail because the page looks wrong. It fails because someone checked the address bar first.
Attackers can copy a logo, a layout, a login form, and the wording of a real notification exactly. What they cannot copy is the real domain. That single fact is what the rest of this guide is built on.
Check the domain, not the design.
Read the domain right to left
Every web address has one part that cannot be faked: the registered domain. It sits immediately to the left of the first single slash, and you read it right to left.
- In
accounts.google.com/signin, the registered domain is google.com. Everything to the left of it —accounts— is a subdomain that Google controls. - In
google.com.secure-login.xyz/signin, the registered domain is secure-login.xyz. Thegoogle.compart is just a subdomain the attacker chose because it reads convincingly from left to right.
That second pattern is the most common trick in phishing, and it works because we read addresses the way we read sentences. Train yourself to skip to the end instead: find the first single slash, then take the two words to its left. That is the site you are actually on.
Before you click
- Hover, or long-press on mobile. Both reveal the real destination. Link text is decoration and can say anything.
- Treat shortened links as unknown. A shortened link hides its destination by design. That is fine for a newsletter you subscribed to, and not fine for an unexpected message about your account.
- Look for extra words bolted onto a brand. Real companies do not sign you in at
paypal-verify-account.comorapple-id-locked.net. - An unexpected link is unconfirmed even from someone you know. Compromised accounts are the delivery method for a lot of phishing. The message being genuinely from your friend's address does not mean your friend sent it.
If you are already on the page
- Read the address bar before you type anything. This is the last moment where checking is free.
- Ignore the padlock. It means the connection is encrypted, not that the owner is trustworthy. Certificates are free, so nearly every phishing site has one.
- Let your password manager decide. A password manager fills credentials only on the exact domain it saved them for. If it does not offer to fill on a page where it normally would, take that seriously — it noticed something you did not.
- Question any sign-in prompt that should not be there. An invitation, a delivery notice, or a shared document has no reason to ask for your email password. When a page asks you to sign in with Google or Microsoft to view something unrelated, that is the attack.
The one-minute version
When the stakes are real — money, a payment detail, an account you care about — do not evaluate the link at all. Go around it.
- Arrive on your own. Open a new tab and type the address yourself, or use your bookmark or the company's app. If the message was legitimate, whatever it wanted you to see will be waiting for you there.
- Confirm through a channel you already had. Call the number on the back of your card. Reply in a message thread that existed before today. Walk down the hall.
- Never use contact details from the message itself. If the message is fake, so is the phone number in it.
Three tells that mean stop
- The registered domain in the address bar is not the brand's real one.
- You are asked to sign in with an unrelated account to view a file, invitation, or delivery notice.
- Something downloaded on its own, especially a
.exefile. Do not open it.
If you already typed your password
You are not the first, and moving quickly matters more than feeling bad about it.
- Change that password now, on the real site, reached by typing the address yourself.
- Sign out of other sessions. Most account security pages list active devices and let you revoke them.
- Turn on two-factor authentication, using an authenticator app or hardware key rather than SMS.
- Check your email forwarding rules. Attackers add them to keep reading your mail after you have locked them out.
- Warn anyone who might get the same message from you if the compromised account was your email.
Summary
- The registered domain is the answer — immediately left of the first single slash, read right to left.
- Lookalike subdomains are the main trick.
google.com.secure-login.xyzis not Google. - The padlock proves encryption, not honesty.
- Your password manager is a better detector than your eyes.
- When it matters, go around the link rather than judging it.
None of this requires expertise, and all of it takes less time than recovering an account does. If you are not sure about a link, an email, or a site, run a free Quick Check with Carmen — paste it in and you will get a read on it in seconds.