The strongest phishing judgement comes from combining destination, message context, page behaviour and independent verification.
Start with the hostname
Read from right to left around the registered domain. A brand name placed in a subdomain or path does not make that company the owner. Watch for substituted characters, extra words, unfamiliar country domains and link shorteners.
Compare the request with normal behaviour
Unexpected password resets, invoices, shared documents and urgent account warnings are common lures. Be cautious when the message creates pressure, asks for a one-time code or sends you to a login page you did not request.
Inspect the page signals
- Does the form submit to an unrelated hostname?
- Does the page imitate a brand while using a different domain?
- Does it request credentials or payment details unusually early?
- Does the route pass through unrelated redirectors?
Do not rely on appearance alone
Logos and polished layouts are easy to copy. Certificate padlocks and valid TLS are also available to attackers. Verify the request by navigating independently to the organisation’s official site or app.
Further reading: CISA phishing guidance.