Guide · 3 min read

How to read a web address, and why almost everyone reads it wrong

The single rule that defeats most phishing links, explained properly — plus the four checks worth doing before you type anything into a page.

Almost every phishing link relies on one habit: people read a web address left to right, and stop as soon as they see a name they recognise.

The rule

The owner of a page is the label immediately before the first single slash. Read from that point, not from the start.

In `https://paypal.com.secure-login.top/signin`, the owner is `secure-login.top`. The `paypal.com.` at the front is text somebody typed. Anyone can put any brand there; it costs nothing and means nothing.

The genuine address has that name at the end with nothing after it: `paypal.com/signin`.

Four checks

Do not follow the link you were sent. Search for the company, or open the app you already have. Everything a real company needs from you works from a page you navigated to yourself.

Check how old the domain is. Credential-harvesting domains are usually days old. A company you have heard of does not have a brand-new address.

Nobody legitimate asks for a recovery phrase. Not a wallet, not support, not "verification". That request is not a warning sign — it is the whole scam.

A job application does not need your passport up front. Identity documents and bank details come after an offer, through an HR system. On an application form they are the product being collected.

If you want the checks run for you

Our free checker does the ones that need data you do not have: registration age from the domain registry, hosting and network from the routing registry, the certificate, and whether public phishing feeds already list it. It reports what it observed and lets you decide — it will not tell you a site is safe, because no automated check can honestly promise that.