Phishing websites are built for one purpose: to trick you into handing over your passwords, card numbers, or personal details by impersonating a company you trust. And they're getting scarily convincing — a modern phishing page can look identical to a real bank or login screen. The good news is that phishing sites almost always leak clues, and once you know what to look for, they're much easier to catch. Here are 10 red flags that reveal a phishing website before it can do any damage.

Most phishing starts with a message — an email, text, or DM — pushing you to click a link "right now." A genuine company rarely sends an urgent, out-of-the-blue link demanding you log in. If you didn't expect the message, treat the link with suspicion and, when in doubt, navigate to the site yourself by typing the real address instead of clicking.

2. The URL doesn't quite match the real brand

This is the single biggest tell. Phishers register look-alike domains — paypa1.com, amaz0n-security.com, netflix-billing.net — hoping you won't look closely. Read the domain carefully, character by character, and watch for subdomain tricks: in apple.com.verify-login.ru, the real domain is verify-login.ru, not Apple. The true domain is always the part just before the first single slash.

3. Urgent or threatening language

"Your account will be suspended in 24 hours." "Suspicious login detected — verify now or lose access." Phishing relies on panic to stop you thinking clearly. Real companies don't threaten you into instant action through a link. Manufactured urgency is one of the clearest warning signs.

4. It asks for sensitive information it shouldn't need

Be extremely wary of any page asking for your password, full card number, PIN, one-time passcode (OTP), or Social Security number — especially one you reached from a link. Legitimate services almost never ask you to confirm these details this way, and no honest site needs your OTP typed into a web form.

5. The login page looks slightly "off"

Phishers copy login pages, but small details slip. Look for a slightly wrong logo, off-brand colors, odd fonts, blurry images, or a layout that doesn't quite match what you remember. If a familiar login screen feels subtly wrong, trust that instinct.

6. Spelling and grammar mistakes

Professional companies proofread their sites. Phishing pages are often riddled with awkward phrasing, misspellings, and grammatical errors — a strong signal you're not on the real thing.

Before clicking anything on a suspicious page (or in the email that led there), hover over links to preview the real destination. If the visible text says one thing but the actual URL points somewhere unrelated, that mismatch is a hallmark of phishing.

8. Requests for unusual payment methods

Any site demanding payment by gift card, cryptocurrency, or wire transfer — or asking you to "verify" your identity with a payment — is almost certainly a scam. Legitimate businesses don't operate this way. These payment methods are favored precisely because they're hard to trace or reverse.

9. Too-good-to-be-true offers

"You've won a prize!" "90% off — today only!" "Claim your refund now!" Phishing sites dangle irresistible rewards to lure you into entering details or downloading something. If an offer seems too good to be true, it is.

10. Missing HTTPS — or HTTPS you're leaning on too much

A phishing site with no padlock and plain http:// asking for your data is an obvious danger. But here's the crucial nuance: HTTPS alone does not mean a site is safe. Scammers get free certificates too, so a padlock on a look-alike domain proves only that the connection is encrypted — not that the site is honest. Our guide on HTTP vs HTTPS explains why the padlock is necessary but not sufficient.

How to verify a suspicious site

If a site trips several of these flags, confirm before you trust it:

What to do if you spot a phishing site

Don't enter anything. Close the tab, and if the link came from an email or text, don't reply or click anything else in it. If you've already entered credentials, change that password immediately (and anywhere you reused it), enable two-factor authentication, and watch your accounts for unusual activity. You can also report phishing pages to the impersonated company and to your browser, which helps get them taken down.

The bottom line

Phishing websites survive on speed and panic — they want you to click and type before you think. Slow down and run through these 10 red flags: an unexpected link, a look-alike URL, urgent threats, requests for sensitive data, an off-looking login page, poor grammar, mismatched links, odd payment demands, unbelievable offers, and over-reliance on a padlock that proves nothing about honesty. Spot even a couple of these, and the safest move is always the same — close the tab and go to the real site directly.