Almost every phishing message, fake-shop ad, and "your account is locked" text has the same weak point: the link. Attackers can copy a logo, clone a login page pixel-for-pixel, and even earn a valid security certificate — but they can't register the real company's domain. So they register something that looks like it. Learning to read a web address is the single highest-leverage habit in online safety, and it takes about half a minute.
First, the one rule that matters most
A web address is read right-to-left, not left-to-right. The part that decides who owns the page is the two labels sitting immediately before the first single slash — the registrable domain.
https://login.secure-billing.info/paypal/verify
Your eye lands on "login" and "paypal" and feels safe. But the owner is secure-billing.info. Everything before it (login.) is a subdomain the attacker controls, and everything after the slash (/paypal/verify) is just a folder name they typed. Find the real domain first, every time.
Six red flags in a suspicious link
The brand name is in the wrong place
This is the trick that fools the most people. paypal.com.secure-login.info is not PayPal — the real owner is secure-login.info, and 'paypal' is just a subdomain they bolted on the front. The registrable domain is always the two labels touching the final .com / .org / .net, immediately before the first single slash. Read a URL right-to-left, not left-to-right. If the familiar name isn't in that final slot, you're not where you think you are.
Letters that almost look right
rnicrosoft.com uses r-n to fake an m. app1e.com swaps the letter l for the digit 1. paypa1.com, arnazon.com, goggle.com, netflx.com — these typosquats bank on your eye autocorrecting. Slow down and read the domain one character at a time. Norton's fraud team lists character substitution as one of the most common signals of a fake site.
A domain that starts with xn--
Internationalized domains let non-Latin scripts into web addresses, and browsers store them as punycode — an ASCII form that begins with xn--. Attackers exploit this with homograph attacks: a Cyrillic 'а' or Greek omicron that renders pixel-for-pixel like a Latin letter, so аpple.com looks identical to apple.com but resolves somewhere else entirely. Most modern browsers now show the raw xn-- version when they detect mixed scripts. If a link you expected to be a plain English brand suddenly shows xn-- in the address bar, treat it as hostile.
The padlock proves nothing
The 'look for the padlock' advice is a decade out of date. Free, automated certificate authorities mean a phishing page can show HTTPS and a padlock within minutes of going live. The lock confirms the connection is encrypted — not that the site is honest. Judge the domain name and its age, never the padlock.
Extra words glued to a real brand
amazon-support.com, apple-verify.net, paypal-secure.co — combosquatting adds a plausible word (support, login, verify, billing, help) to a real brand on a domain the brand doesn't own. The legitimate company almost always keeps these on its own root domain (amazon.com/support), not on a separate hyphenated address. A brand name plus a security-flavored word on a brand-new domain is a classic phishing shape.
Raw IP addresses, @ signs, and odd endings
A link that points to a bare number like http://192.0.2.14/login has no domain to trust at all. An @ inside a URL (http://apple.com@evil.site) sends you to whatever comes after the @, ignoring everything before it. And unusual top-level endings — long strings of random characters, or cheap TLDs bulk-registered for abuse — deserve extra suspicion when they're wearing a familiar brand's name.
Two free checks when you're still not sure
If the domain reads clean but something still feels off, two lookups settle most cases in under a minute:
- Domain age (WHOIS). Look up the domain on any WHOIS service. A site claiming to be a household name that was registered last Tuesday is almost always a scam. Established brands own their domains for years or decades.
- A reputation scanner. Free tools like Google Safe Browsing, VirusTotal, or a phishing-link checker will flag a URL that's already been reported. A clean result isn't a guarantee — brand-new phishing sites haven't been reported yet — but a positive hit is decisive.
The safest move of all needs no tools: when a message pushes you toward a link, don't use the link. Open a new tab and type the address you already know, or search for the company and click its official result. Attackers rely on you clicking their path — take your own.
Why the address bar still wins
Phishing keeps getting better at everything except one thing: the domain. A page can be a flawless clone and still have to live somewhere, and that somewhere is written in plain sight at the top of your browser. CISA's guidance on avoiding phishing comes down to the same instinct — slow down, don't trust the framing of an urgent message, and verify the destination yourself before you hand over anything. The link is where the lie lives, and it's also where it's easiest to catch.
Not sure a claim or link is real?
FAXTR searches 100+ fact-checking organizations in one query — free, no login required. Check a viral claim before you trust the site pushing it.