How to Spot a Fake Website: 10 Red Flags in a URL
How to Spot a Fake Website: 10 Red Flags in a URL
Most online scams start with a single link. A text message, an email, an ad, a search result — one tap and you land on a page that looks exactly like your bank, your delivery service, or your favorite store. The page is fake. The login box is a trap. And by the time you notice, your password (or your money) is already gone.
The good news: fake websites almost always leave clues in the address bar. Once you know what to look for, you can catch most of them in a few seconds — before you type anything. Here are the ten red flags that give a fake website away.
1. Look-alike or misspelled domain names
Scammers register domains that look right at a glance: paypa1.com (a number "1" instead of the letter "l"), arnazon.com ("rn" pretending to be "m"), faceb00k.com. Slow down and read the domain letter by letter. If anything is swapped, doubled, or misspelled, leave.
2. The real domain isn't where you think it is
This is the trick that fools the most people. Look at:
paypal.com.secure-login.xyz
Your eye sees "paypal.com" and relaxes. But the real domain is always the part right before the top-level ending — here that's secure-login.xyz, not PayPal. Read a web address right to left: find the ".com/.xyz/.net" ending, and the word immediately before it is the true owner of the site.
3. An "@" symbol in the link
Everything before an @ in a URL is ignored by your browser. So a link like https://paypal.com@evil-site.ru/login does not go to PayPal — it goes to evil-site.ru. If you see an @ in the middle of a web address, treat it as hostile.
4. A padlock does NOT mean "safe"
You were probably told to "look for the padlock." That advice is outdated. The padlock (HTTPS) only means the connection is encrypted — it says nothing about who is on the other end. Today the large majority of phishing sites have a padlock too, because certificates are free. A missing padlock is a bad sign; a present padlock is not a good one.
5. Strange characters in a familiar name (homograph attack)
Some letters in other alphabets look identical to English ones. An attacker can register аpple.com using a Cyrillic "а" that your eye reads as a normal "a." In the address bar these sometimes show up as a domain starting with xn--. If a well-known brand's address suddenly contains odd characters or an xn-- prefix, it's a fake.
6. Odd endings and free hosting posing as a brand
Big companies use their own domains. Be suspicious when a "bank" or "courier" page lives on a random free subdomain (your-bank.weebly.com, dhl-tracking.rf.gd) or on a cheap, throwaway ending like .zip, .top, or .click. Legitimate brands rarely run their login pages on hosting like that.
7. The link text and the real destination don't match
On a computer, hover your mouse over a link (don't click) and look at the address your browser shows at the bottom of the screen. On a phone, press and hold the link to preview it. If the visible text says one thing but the real destination is somewhere else entirely, that mismatch is the scam.
8. Shortened links that hide where they go
Short links (bit.ly, tinyurl, and similar) are convenient — and perfect for hiding a destination. If a stranger, an ad, or an urgent message sends you a shortened link, don't click blind. Expand it first with a link-preview/expander service, or simply go to the site yourself.
9. A raw IP address instead of a name
Real services use names, not numbers. A link like http://185.203.44.17/verify pointing at your "bank" is almost always malicious. Numbers in place of a domain name are a strong warning sign.
10. Urgency, threats, and pages that just want your password
"Your account will be suspended in 24 hours." "Confirm now or lose access." Fake sites manufacture panic so you act before you think. Combine that pressure with a page whose only purpose is to collect your login or card details, and you're looking at phishing. Real companies don't threaten you into a random link.
The 10-second safe-check habit
You don't need to memorize all ten. Build one habit instead:
- Don't click first. Hover (desktop) or long-press (mobile) to reveal the real address.
- Read the domain right to left and confirm the true owner — the word just before .com/.net/.xyz.
- Never enter a password or card number on a page you reached from a link or message.
- Go there yourself instead: open the official app, or type the address / use your own bookmark.
- Verify by a second channel if in doubt — call the number on the back of your card, not the one in the message.
Being careful vs. being trained
The checks above are consumer-level self-defense — enough to keep you and your family safe from the everyday scams. But recognizing a fake URL is the very first thing security professionals learn on the way to spotting phishing, malware delivery, and full-blown intrusions.
Curious about doing this for a living?
If defending systems (not just yourself) sounds like your kind of thing, a foundation like CompTIA Security+ is where most people start. See the exam-prep paths on CertInstructor →
Written by the team at Security365 / CertInstructor — 20+ years training cybersecurity professionals, holders of the full CompTIA security certification stack, and recipients of the EC-Council Instructor Circle of Excellence Award (two years running).
Comments
Post a Comment