Phishing Awareness

🔍 How to Detect a Fake Login Page

By Sophie Laurent, Hobbyist with a keen interest in password security and online safety, Trusty Password · 2 May 2026 · 3 min read · 223 words

Fake login pages are the most common tool used in credential theft. An attacker creates a convincing copy of a real login page and tricks you into entering your credentials — often through a phishing email, a malicious advertisement, or a compromised website that redirects to the fake page. The quality of these fakes has improved dramatically: modern phishing kits can clone a real login page in seconds, copying everything from the logo and colour scheme to the form behaviour and error messages.

Because visual inspection is no longer reliable, detecting a fake login page requires a combination of technical checks and smart habits. This guide covers the six most effective techniques you can use to tell a fake login page from the real thing.

The Domain Name Is Everything

The single most reliable indicator of a fake login page is the domain name in your browser's address bar. No matter how convincing the page looks, if the domain does not match the official website of the service, you are on a fake. Attackers use three primary techniques to make fake domains look convincing: subdomain deception (e.g., login-paypal.com.attacker-site.com), typosquatting (e.g., g00gle.com instead of google.com), and homograph attacks that replace Latin letters with visually identical characters from other writing systems.

Before entering any credentials, take two seconds to read the domain from right to left. Identify the top-level domain (.com, .org, .net) and then the root domain immediately to its left. That root domain — and only that root domain — identifies the true owner of the website. If you are trying to log into PayPal, the root domain must be "paypal.com". Anything else is a fake, regardless of how convincing the page looks.

Check for HTTPS — But Do Not Trust the Padlock Alone

A padlock icon in the address bar and a URL beginning with "https://" indicate that the connection between your browser and the website is encrypted. This is good — it means your password cannot be intercepted in transit. However, it does NOT mean the website is legitimate. Free TLS certificates from services like Let's Encrypt mean any attacker can obtain a valid HTTPS certificate for their phishing domain at no cost. A 2024 study found that over 80% of active phishing sites use HTTPS, up from just 20% a few years ago.

The padlock only tells you the connection is encrypted, not that you are on the right website. Treat the presence of HTTPS as a neutral signal — neither good nor bad — and rely on domain verification instead.

The Password Manager Autofill Test

One of the best technical tests for a fake login page requires no effort at all: just see whether your password manager offers to autofill your credentials. Password managers like NordPass store credentials keyed to specific domains. When you visit a page, the password manager compares the domain to its stored entries. It will only offer to autofill if the domain matches exactly. If you are on "paypa1.com" instead of "paypal.com", the password manager stays silent — a clear red flag.

This test catches subdomain spoofing, typosquatting, and homograph attacks that might fool the human eye. If your password manager does not offer to fill, do not proceed with manual entry. Navigate directly to the service you intend to use by typing the URL yourself.

Check the Page's Behaviour

Fake login pages often behave differently from legitimate ones in subtle ways. Here are a few behavioural cues to watch for:

Verify HTTPS Certificate Details

For a more advanced check, click the padlock icon in your browser's address bar and view the certificate details. Legitimate websites operated by established organisations typically have Extended Validation (EV) or Organisation Validation (OV) certificates that include the verified legal name of the organisation. If the certificate shows an organisation name that does not match the expected service, or if it shows "Not Verified" or a generic domain-validated certificate for a site that should have EV, that is a warning sign.

This check is not foolproof — many legitimate services now use domain-validated certificates that show no organisation name — but it is an additional data point. If you see an organisation name that clearly does not belong to the service you are trying to reach, do not proceed.

What to Do If You Have Entered Credentials on a Fake Page

If you realise that you have entered your credentials on a fake login page, act immediately. The attacker may have already automated the credential capture and begun testing it against other services. Follow this response protocol:

  1. Navigate directly to the real website — type the URL manually, do not click any links.
  2. Change your password immediately to a new, unique, randomly generated password.
  3. Revoke all active sessions from the account's security settings.
  4. Enable or rotate multi-factor authentication (MFA) — especially if it was not enabled before.
  5. Check other accounts where you may have reused the same password and change those too.
  6. Report the phishing site to help protect others: the NCSC accepts reports at report@phishing.gov.uk.

For ongoing protection, consider using a comprehensive security suite like Kaspersky Premium which includes real-time anti-phishing protection that blocks fake login pages before you enter credentials. And if you are not already using a password manager, NordPass helps ensure that even if you are tricked once, the damage is contained to a single account with a unique, unreusable password.

Conclusion

Fake login pages are becoming harder to spot with the naked eye, but they have not become impossible to detect. By combining domain verification, the password manager autofill test, behavioural checks, and certificate inspection, you can reliably distinguish legitimate login pages from phishing attempts. The most important habit is pause and verify before typing your credentials — that split-second check is often the difference between staying safe and becoming a victim.

Generate a Free Strong Password →

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🛡️ Best Password Generator🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder⚙️ StrongPassFactory🔑 SecureKeyGen.org📚 TrustyPassword.org
We use cookies to improve your experience. Learn more