You can identify most phishing websites by checking how you got there, reading the real domain name, and noticing what the page asks for. A fake site usually arrives through a link in a message, sits on a lookalike or unrelated domain, and asks for a login, card number or OTP straight away. The padlock icon proves nothing about who runs the site.
Phishing websites are made in bulk. The Anti-Phishing Working Group counted 1,069,681 phishing attacks in the second quarter of 2026 in its Phishing Activity Trends Report. The same report shows which sites get copied most: webmail and software logins made up 29.1% of attacks, payment services 13.2%, banks and other financial institutions 11.4% and logistics and shipping 9.6%. So the page you are most likely to meet is a fake email login, a payment page or a parcel tracking page.
8 checks for a phishing website
1. How did you get to this page?
This is the most useful check of all. If you arrived by tapping a link in an email, SMS, WhatsApp message, social media post or search ad, slow down. If you typed the address yourself, used a bookmark or opened the official app, the risk is far lower. Most phishing pages are never found by browsing; they are delivered.
2. Read the domain from right to left
The part that matters is the registered domain: the name directly before the ending, such as .com, .in or .co.in. In secure-login.mybank.example.com, the site belongs to example.com, not to mybank. Brand names placed on the left, in the path after the slash or inside a long string of words are decoration.
3. Look for lookalike spelling
Attackers register names that pass a quick glance: a digit 1 for a letter l, rn for m, an extra word such as “verify”, “kyc” or “support”, or a different ending. On a phone the address bar is short, so tap it and read the whole name.
4. Don’t treat the padlock as a trust mark
The padlock means the connection is encrypted. It says nothing about who is on the other end. Certificates are free and automatic: Let’s Encrypt, a free certificate authority, states that anyone who owns a domain name can get a trusted certificate from it at zero cost. Phishing sites use them routinely.
5. Notice what the page asks for, and when
A real bank login asks for your user ID and password, then sends an OTP for a specific action you started. A phishing page often asks for everything on one screen: password, card number, expiry date, CVV, ATM PIN and the OTP. Any page that wants your full card details “to verify your identity” is fake.
6. Watch your password manager
A password manager fills in passwords only on the exact domain where you saved them. If it offers nothing on a page that looks like your bank, the domain is different from the one you normally use. That silence is one of the strongest signals you can get.
7. Test the rest of the site
Fake sites are often a single page. When we analysed a phishing page aimed at a Philippine bank’s customers in 2017, it had no home page and no contact page, and every link on it was dead. Click the logo, the footer links and the “forgot password” link. If they lead nowhere or back to the same form, leave.
8. Check the domain’s age
A WHOIS or RDAP lookup shows when a domain was registered. A bank or large retailer has had its domain for years. A login page on a domain registered last week is almost certainly not theirs. Search results and ads are not proof either, because scammers buy ads and copy page titles.
What to do if you entered details on a phishing site
- Change the password from the official app or by typing the real address, and turn on two-step verification.
- If you entered card or bank details, call your bank’s official number to block the card or account.
- In India, report money lost on the 1930 helpline or at cybercrime.gov.in.
- Report the fake page to Google Safe Browsing, so browsers start warning other visitors.
If you got there from an email, our checklist on how to identify a phishing email helps you spot the next one before you click.
For brands: when the fake site uses your name
When a phishing site copies your login or checkout page, your customers lose money and you lose trust. Organisations in India also have a reporting duty: CERT-In’s Directions of April 28, 2022 list identity theft, spoofing and phishing attacks among the incidents that must be reported within six hours of noticing them, at incident@cert-in.org.in.
The fastest fix is removing the site. That means evidence, the right abuse contacts at the registrar, host and any proxy in front of it, and follow up until the page is gone. Our explainer on how a phishing operation works shows each link in that chain. TIKAJ’s takedown service runs the process end to end, and TIKAJ and Hunto handle more than 100,000 takedowns a year for over 150 enterprise customers.
FAQ
Does a padlock mean a website is safe?
No. The padlock only means the connection between your browser and the site is encrypted, so others on the network can’t read it. Anyone who owns a domain can get a free certificate in minutes, including criminals. A phishing site with a padlock still sends your password straight to the attacker. Check the domain name and how you arrived instead.
Can a phishing website use a .com or .in address?
Yes. Attackers register ordinary .com, .in and .co.in names that look like a real brand, and they also hide pages on hacked websites and free hosting platforms. The ending tells you nothing about safety. What matters is whether the registered domain, the name directly before the ending, is exactly the one the real company uses.
How can I check a suspicious link without opening it?
On a computer, hover over the link and read the address that appears at the bottom of the browser. On a phone, press and hold the link to preview it without opening. Then read the registered domain from right to left. If you still aren’t sure, don’t use the link at all: type the company’s address yourself or open its official app.
