Phishing
How to recognise a phishing page
Phishing pages copy a familiar design and rely on urgency. Learn how to read a web address, which signals actually matter, and what to do if you already typed your password.
Updated 8 min readqikfox
The short answer
A phishing page is a copy of a site you trust, hosted at an address the real organisation does not control. The reliable way to spot one is to read the domain immediately to the left of the first single slash in the address bar, and to distrust any page that arrived through a message pressing you to act quickly. Design quality, padlock icons and spelling are not dependable signals.
Key points
- Read the domain, not the design: the domain is the text just before the first single slash in the address.
- A padlock only means the connection is encrypted; criminals encrypt their sites too.
- Urgency is the shared ingredient of nearly every phishing attempt, because it discourages checking.
- If a message asks you to sign in, open the service yourself from a bookmark instead of using the link.
- If you already entered a password, change it on the real site and sign out other sessions before anything else.
What phishing actually is
Phishing is impersonation. Someone builds a page that looks like a service you already use - a bank, a delivery company, a workplace login, a social account - and then finds a way to put a link to it in front of you. Nothing is broken into and nothing is hacked. The page simply collects whatever you type and passes it to whoever built it.
Because the technique depends on you believing the page, attackers put their effort into appearance and context rather than technology. Logos are copied pixel for pixel. Fonts match. Some pages even forward you to the genuine site after you submit, so that the login you attempt second appears to succeed and nothing feels wrong.
This is why advice about spelling mistakes and blurry logos has aged badly. Those flaws were common when phishing kits were hand-made. Today the visual copy is usually accurate, and the only thing an attacker cannot copy is the address of the real site.
How to read a web address
Every web address has one part that determines who is answering: the registered domain, sitting immediately to the left of the first single slash. Everything after that slash is chosen freely by whoever runs the site, and everything before it can be padded with words designed to reassure you.
Consider an address such as login.examplebank.com.account-verify.example: it ends at account-verify.example, so that is the site you are talking to, no matter how many trusted-looking words appear earlier. The reverse is also true - examplebank.com/login/secure/verify is the real bank, because the domain still ends at examplebank.com.
- Find the first single slash in the address, then read backwards to the start of that word group.
- Look for lookalike characters, hyphenated additions and extra endings appended to a familiar name.
- Treat subdomains as decoration: anyone can create any subdomain on a domain they control.
- On mobile, tap the address bar to see the full address; truncated addresses hide the ending that matters.
Signals that do not work any more
The padlock icon tells you the connection between your device and that server is encrypted. It says nothing about who owns the server. Certificates for encryption are free and issued automatically, so a deceptive page is as likely to be encrypted as a genuine one.
Search results are not a safety check either. Paid placement and freshly built sites can both appear above the organisation you were looking for, particularly for queries like a company name followed by the word login.
Finally, familiarity is not verification. Receiving a message from a thread you recognise, or from a colleague's address, means only that someone already has access to that thread or address.
The one habit that removes most of the risk
Never sign in through a link you did not choose. When a message says your account needs attention, close it, open the service the way you normally would - a bookmark, a typed address, or the app - and look for the same notice there. If the notice is real, it will be waiting for you. If nothing is waiting, the message was not real.
This single habit defeats phishing regardless of how convincing the page is, because it removes the attacker's only delivery route. It also costs almost nothing once it becomes reflexive.
Pair it with a password manager. A manager fills credentials based on the domain, so it silently refuses to autofill on a lookalike address. That refusal is often the first hint that something is wrong.
How qikfox approaches this
qikfox Safe Browser checks pages against known-deceptive-page signals and interrupts before the page loads rather than after. The warning states what was detected and offers a clear route back, because a warning that only says danger teaches nothing and gets clicked through.
qikfox Search surfaces safety context alongside results, so the decision can happen before the click instead of after it. Protection controls live on one screen in the browser's protection panel, described in plain language, so you can see what is on rather than hunting through nested menus.
None of this replaces the habit above. Blocklists always trail new pages by some interval, which is exactly the interval an attacker aims to exploit.
If you already entered your password
Act in order and do not spend time on self-reproach; speed matters more than diagnosis. Change the password on the genuine site first, because that invalidates what the attacker collected. Then sign out other sessions, which most services offer in security settings.
Next, turn on strong authentication if it is available, so a stolen password alone is not enough. Then change the same password anywhere else you used it - reuse is what turns one mistake into several. Finally, watch the account for a few weeks for changed recovery addresses or unexpected devices.
- Change the password on the real site.
- Sign out all other sessions.
- Turn on two-step or passkey authentication.
- Replace that password anywhere it was reused.
- Check recovery email, phone number and connected devices.
Questions and answers
Related qikfox pages
qikfox Safe Browser safety
How warnings and page checks work in the browser.
What a scam message looks like
The three pretexts behind most scam messages.
qikfox Search
Safety context before the click.
Help Center
Product-specific answers.
Back to Guides · Written and reviewed by the qikfox editorial team. Published .
Put the advice into practice
qikfox Safe Browser applies most of what this article describes by default, and works alongside qikfox Search, Antivirus and VPN.