How to identify a phishing link
Almost every account takeover starts with a link that looked fine. The good news is that a phishing link almost always gives itself away in its own text — if you know which part of it to read.
The short version
- Read the domain immediately before the first single slash — that is the real site.
- A padlock means the connection is encrypted, not that the site is honest.
- Hyphens and extra words in a brand's domain are the most common tell.
- Never log in from a link in a message; open the app or type the address yourself.
Where the real domain actually is
A web address is read from a specific point, not left to right. Find the first single slash after the https:// part, then read backwards from it. The last two labels before that slash are the real domain — everything else is decoration the sender controls.
So in https://secure.icicibank.com.verify-login.in/account, the real domain is verify-login.in, not icicibank.com. The bank's name is sitting in a subdomain, which anyone can create on their own domain in seconds. This single trick accounts for a huge share of successful phishing, because the eye stops at the first familiar word it sees.
Practise it on links you trust and it becomes automatic. Our link decoder shows you the parsed domain of any link so you can check your reading against it.
The lookalike tricks worth knowing
Extra words joined by hyphens: paytm-verify.com, sbi-kyc-update.in. A real company almost never needs a second domain to verify you — it uses the one you already know.
Character swaps that survive a glance: rn for m, l for I, 0 for o. flipkart with a capital I instead of an l is a different domain and looks identical in most fonts.
A different top-level ending on a familiar name: amazon.co.in is real, amazon-in.net is not. If the ending is unfamiliar, treat the whole link as unfamiliar.
Shortened links (bit.ly and friends) hide all of the above. A shortener in a message about money or an account is a reason to stop, not a neutral convenience.
What the padlock does and does not mean
HTTPS and the padlock icon confirm one thing: traffic between you and that server is encrypted. They say nothing about who owns the server. Certificates are free and issued in minutes, so the overwhelming majority of phishing pages now have a perfectly valid padlock. "Look for the padlock" was useful advice fifteen years ago and is actively misleading today.
The five-second check
On a computer, hover over the link and read the address that appears at the bottom of the window before clicking. On a phone, press and hold the link until a preview appears, then read it. Do not tap.
Read the domain using the rule above. If it is not exactly the domain you expect, stop.
Then apply the habit that makes the whole question moot: never sign in from a link you were sent. Open the app, or type the address you already know into the address bar. A real notification will still be waiting for you inside the app.
When the link looks clean and still is not
A brand-new phishing domain has no reputation, no history, and nothing for a checker to flag — it can look completely ordinary. That is why the login habit matters more than any tool: it removes the need to judge the link at all. Our checkers will catch a large share of bad links, and they are a second opinion, never a permission slip.
Nothing on this site will ever ask for your password, OTP or recovery codes.
Related guides
Want this handled for you?
Our engineers do this work for businesses every day, on monitoring platforms built to catch it earlier. Describe your situation and we will tell you what would actually help.
Talk to Our Security Team