All scamsPhishing
Lookalike domain
URLs that look like a brand you trust, with one or two characters off.
How it works
Attackers register domains like paypa1.com, arnazon.com, or microsoft-secure-login.com and host pixel-perfect copies of the real site to harvest logins.
Red flags
- Numbers replacing letters (1 for l, 0 for o)
- Hyphens between brand and a generic word
- Brand on an unusual TLD (.zip, .top, .click)
Real-world example
"https://account-secure-microsoft.click"
What to do
- 01Always type the brand's URL yourself or use a saved bookmark.
- 02Use a password manager — it won't autofill on lookalike domains.
- 03Report phishing pages to Google Safe Browsing.
Related scams
Got a message that looks like this?
Paste it into the detector for a personalised analysis and next steps.
Open the detector