If you can only check one thing about a suspicious address, check how old it is. Credential-harvesting domains are almost always days or weeks old, because they get blocked and replaced constantly. A company you have heard of does not have a brand-new domain.
It is also free. RDAP — the successor to WHOIS — is published by the registries themselves, needs no key, and answers in a second.
Reading the record
Registration date. The headline number. Under 30 days on a page asking for a password is close to conclusive when combined with anything else.
Registrar. Not an accusation — every budget registrar has a large legitimate customer base — but corporate registrars and bulk-abuse registrars have visibly different customer mixes.
Status codes. `clientHold` or `serverHold` means the registrar or registry has *already* suspended the domain, usually after an abuse complaint. Somebody reported it before you.
Registrant identity. Usually redacted since GDPR. That absence means nothing at all, and any tool presenting "REDACTED FOR PRIVACY" as a finding is showing you the law rather than a fact about that domain.
Certificate age is sharper
Registration age has a blind spot: a domain can sit parked for years and be turned into a phishing page last Tuesday. The TLS certificate is when the site actually started serving. Where the two disagree — an old domain with a certificate issued yesterday — the certificate is telling you more.
And the archive is sharper still for the opposite question
To confirm something is *real*, the Internet Archive is the best free source. Nine years of snapshots is a public history that cannot be manufactured after the fact. No snapshot at all, on a commercial site, means it is either very new or has never had visitors.