Pharming: when the right address sends you to a fake site
Most phishing needs you to click a bad link. Pharming does not. It poisons the path between a correct address and the real server, so you can type the right domain — or click a genuine bookmark — and still end up on a fake site. That is what makes it unsettling: the address looks right.
How pharming works
When you visit a site, your device translates the name (like bank.com) into a server address using DNS. Pharming tampers with that translation at some point along the way:
- Device hosts file — malware edits a local file to map a real name to a fake server.
- Router compromise — a hijacked home router hands out poisoned DNS answers to everything on the network.
- DNS poisoning — attacks against DNS infrastructure return false answers to many users at once.
Why it is hard to spot
The usual advice — "check the URL" — fails, because the URL is correct. The tells are subtler: a certificate warning on a site that normally has none, small differences in the page, or features that suddenly break. On a properly secured site, a browser certificate error is a serious signal, not something to click through.
Pharming separates the name you trust from the server you reach. HTTPS with a valid certificate is one of the few defences the user can actually see working.
Reducing the risk
- Patch and protect routers and devices — change default credentials, keep firmware current.
- Use reputable DNS and, where available, protected DNS resolution.
- As a brand, enforce HTTPS with HSTS so a downgrade or fake cert is more likely to trigger a warning.
- Heed certificate warnings on familiar sites — treat them as stop signs.
While pharming attacks the resolution path, most brand impersonation still runs on lookalike domains and cloaked clones — which Phish Plug detects and takes down.
The takeaway
Pharming is phishing without the fake link: it corrupts the route from a correct address to the real server. Because the URL looks right, the defences shift to infrastructure hygiene, DNS, and HTTPS — and to treating certificate warnings on trusted sites as the red flags they are.
Keep reading
Related articles
Malvertising: fake ads that impersonate your brand
Attackers buy ads on your own brand terms to outrank you and send customers to clones. How malvertising works and how to detect and take it down.
Read article Email security · 7 minHow to spot a phishing email: the red flags that matter
The reliable signals of a phishing email — and the ones that no longer hold. A practical guide for people, plus why brands can't rely on it alone.
Read article Email security · 9 minDMARC, SPF and DKIM: stop attackers spoofing your domain
Three email-authentication standards decide whether someone can send mail as you. What SPF, DKIM and DMARC do, and how to roll them out without breaking mail.
Read articleRemove the clones targeting your brand
Run a free clone check on one domain — Phish Plug proves the cloaking and files the takedown.