A
lookalike domain imitates a real site's address with a misspelling, added word, different ending or visually similar character. It may host a convincing copy of the real login page. HTTPS can protect the connection to that imitation; it does not turn it into the genuine provider.
A useful example
A message says to sign in at
example-account.test instead of the known
example.com. The page may display the original logo and a working lock icon, yet passwords entered there go to a different operator. Attackers also use subdomains to place the brand at the start of a much longer address.
How to respond
Do not follow the message link. Use a bookmark, the official app or an address you independently know. If you already signed in on the imitation, change the password on the real site and review activity. The
FTC phishing guide describes fake login destinations; our
URL checklist shows how to inspect one.
Practical distinction
A saved bookmark or official app avoids relying on memory for every letter. If a message forces you to use a new address, verify that address independently with the provider before typing credentials.