Phishing URL Examples — Patterns to Recognize
Real phishing links are not shown here. Instead, we describe common patterns so you can recognize suspicious URLs and know when to scan a link with our phishing link checker.
Brand impersonation
Phishers use domains that look like real brands. Patterns include:
- Typos:
paypa1.com,arnazon.com - Extra words:
secure-paypal-login.com,apple-id-verify.com - Wrong TLD:
netflix.support(instead of .com) - Subdomains that look like the brand:
microsoft.otherdomain.com
Always check the real domain (the part right before the path). A link that says “Microsoft” in the text can point to a completely different domain.
Fake login pages
Many phishing links lead to pages that mimic sign-in screens. The URL might look like:
/login,/signin,/verify,/account-updateon a domain that isn’t the real service.- Long query strings that hide the real destination when the link is shortened.
If you didn’t initiate the login (e.g. you didn’t click “Forgot password”), treat unexpected login links as suspicious and scan them before entering any credentials.
Short URLs and redirects
bit.ly, t.co, and other shorteners hide the final URL. Phishers use them so you don’t see the real domain until you’ve already clicked. Use a short URL expander or redirect checker to see where the link goes, then run that final URL through our phishing link checker.
What to do with a suspicious link
Don’t click it. Paste the URL into our phishing link checker to get a verdict. If you already clicked and entered a password, change that password immediately, enable MFA, and report the link if you can.
Try scanning a suspicious link
If you have a link you’re unsure about, paste it into our free phishing link checker. You’ll get a clear verdict and can share the result with others.
Open phishing link checker