Fake login pages, and why they work
A convincing copy of a sign-in page is trivial to make. What actually protects you is not your eyes.
Updated 2026-09-26
Copying a sign-in page is trivial. Anyone can save the real one and change where the form sends your details. There is no visual difference to spot, because there is no visual difference. The page is the real page, with one line changed.
So "look carefully" is bad advice. Here is better advice.
How you actually get there
Nobody searches for a fake login page. You arrive at one because something sent you:
- A link in an email about your account
- A text about a delivery, a fine or a refund
- A sponsored search result above the real one
- A QR code on a poster or a parking meter
- A message from a friend whose account was taken over first
The link is the attack. The page is just the collection point.
What actually protects you
Arrive under your own steam. Open the app, or type the address, or use your own bookmark. A page you navigated to yourself cannot be a page someone sent you. This single habit defeats nearly all of it.
Use a password manager. This is the quiet hero. A password manager fills in credentials by matching the domain. On a lookalike domain it simply will not offer to fill, and that silence is a better warning than anything you could have noticed by eye.
Use passkeys where offered. A passkey is cryptographically tied to the real site's address. A fake site cannot ask for something it is not able to receive. It is the only option on this list that cannot be phished at all.
Treat a code request on a page with suspicion. Fake pages now ask for your two-factor code too, and pass it straight to the real site while it is still valid. If you did not start the sign-in yourself, do not supply the code.
If you have already typed it in
Move quickly, in this order:
1. Change that password, going to the real site yourself. 2. Change it anywhere you reused it. This is where most of the damage happens. 3. Check the account's active sessions and devices and sign out everything you do not recognise. 4. Turn on a second factor if it was not already on. 5. Check for changes the attacker may have made: a forwarding rule on your email, a new recovery address, a changed phone number. People forget this step and get locked out again a week later.
Our password checker tells you whether a password is already circulating in breach data, and runs entirely in your browser — the password never leaves your device.
What a VPN does not do here
Nothing. A VPN encrypts your connection; it does not decide whether the site at the other end is honest. Anyone telling you a VPN stops phishing is selling you something. What helps is a password manager, passkeys, and arriving at sites yourself.
Check a suspicious message Free, and it needs no account.