Fake login pages: how to spot one before you type
A fake login page is the sharp end of phishing — the screen where a moment of trust turns into a stolen password. They are convincing by design, and on a small mobile screen they are harder than ever to catch. Here is how they work, the tells that can give them away, and why the real fix is not asking your customers to be vigilant.
Why they are so convincing
A fake login page is usually an exact copy of the real one. Attackers simply duplicate the front-end — the HTML, the stylesheet, the logo, the layout — and host it on a lookalike domain. There is no technical trick to the appearance; it looks right because it is the same front end. The deception is entirely in the address and the context.
The tells — and their limits
A careful user can sometimes spot a fake. The classic signs:
- The domain is wrong. Your brand may appear in the address, but the real registrable domain is different —
brand.secure-login.netis notbrand.com. - You arrived from a link. Pages reached by tapping a link in an email or text are far riskier than ones you typed or bookmarked.
- Urgency and pressure. "Your account will be closed," "verify within 24 hours" — manufactured panic is a hallmark.
- It asks for too much. A login page that suddenly wants your full card number or extra personal details is a red flag.
The problem: these tells are not reliable. A homoglyph domain can look perfect, cloaking can hide the page from checks, and on mobile the full URL is often truncated. Vigilance helps, but it is not a defence you can depend on.
The credential trap, hidden by cloaking
The dangerous core of a fake login page is the credential trap — the form that captures what the victim types. On a cloaked page, that trap is shown only to real, targeted mobile visitors, while security scanners and crawlers are served a harmless decoy. That is why a fake login page can pass automated checks and still be actively stealing passwords.
signin.brand-account.helpYour session has expired
Re-enter your details to restore access.
EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COMSame URL: a clean page to a scanner (left), the credential trap to a real mobile visitor (right).
Why the brand has to catch them
Expecting every customer to detect a pixel-perfect clone on a look-alike domain — often on a phone, under manufactured pressure — is not a realistic defence. The party best placed to act is the brand being impersonated. By monitoring for clones of its own login pages and removing them quickly, a brand protects every customer at once, instead of hoping each one spots the trap.
What that looks like in practice
- Watch for clones of your sign-in pages and lookalike domains around the clock.
- Resolve the cloak by crawling as both a scanner and a real mobile device, and diff the two.
- Capture evidence of the trap — screenshots, headers, the diff — the moment it is confirmed.
- Take it down fast, across host, registrar and safe-browsing feeds.
Phish Plug does exactly this: it detects cloned login pages, proves the cloaking that hides the trap, and files the takedown — so the fake page is gone before most of your customers ever reach it.
The takeaway
Fake login pages are convincing because they are literal copies, and cloaking lets them hide from the very tools meant to catch them. User vigilance helps but cannot be relied on — especially on mobile. The durable fix is for the brand to watch for its own clones and remove them fast, protecting every customer at once.
Keep reading
Related articles
Brand protection best practices: a checklist for 2026
A practical playbook for protecting your brand from phishing impersonation — monitoring, evidence, takedowns and the metrics that matter.
Read article Threats · 8 minBrand impersonation on social media: a response playbook
Fake profiles, cloned pages and lookalike handles target your customers off your own site. How to find, evidence and take down social impersonation.
Read article Evidence · 7 minWhy a screenshot isn't enough evidence for a takedown
A screenshot is easy to dismiss and easy to fake. What abuse desks actually need — headers, the cloaking diff and timestamps — to act on first submission.
Read articlePut detection and takedowns on autopilot
Run a free clone check on one domain — Phish Plug proves the cloaking and builds the case for you.