Resource icon

Read a login URL before entering your password

A polished login page can still belong to an attacker. Before signing in from a message, QR code or search result, inspect where the browser actually went. A padlock means the connection is encrypted; it does not certify the site's owner.

A four-step URL check​

  1. Tap or click the address bar so the full address is visible. On mobile, do this before typing any password or code.
  2. Find the host between https:// and the next slash. In accounts.example.com/login, the host is accounts.example.com. In example.com.signin-help.test/login, the host ends in signin-help.test; it is not example.com.
  3. Compare the host with the address you know from the provider's app, a saved bookmark or an address you typed yourself. Watch for extra words, swapped letters and unexpected endings. Do not judge by the logo or the words after a slash.
  4. If you cannot confidently identify it, close the page and open the provider directly. Search snippets and sponsored results are not independent proof of the correct address.

A trap that fools quick checks​

A URL can place example.com before an @ sign while the actual host is signin-help.test. The familiar text before the @ is not proof of the destination. Some domains also have multi-part endings, so a simple 'last two words' rule is unreliable. Mozilla's URL guide explains hosts and paths. If you already entered a password, use our recovery steps right away.

Practice with a harmless example​

Open the address bar on a site you already trust and identify the host before the first slash. Then compare it with a link in a message without signing in through that message. This makes the check familiar before you need it under pressure. If the mobile browser hides part of the host, tap the bar to reveal the full address.
Posted by
Jack
Views
6
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack