A fake URL uses a misleading web address to impersonate a company, government agency, login, store, or shared document. Find the registrable domain, compare it with the organization’s known address, and consider why the link was sent before opening it. A logo, brand name, HTTPS padlock, or familiar words elsewhere in the address do not prove ownership.

Which part of a URL identifies the website?

In https://accounts.example.com/security/check?id=42, the website is controlled under example.com. The other parts serve different purposes:

  • https is the connection scheme;
  • accounts is a subdomain chosen by the owner of example.com;
  • /security/check is the path;
  • ?id=42 contains parameters.

Read the domain from right to left. In bank.example-login.com, the controlling domain is example-login.com, not “bank.” A scammer who owns a deceptive domain can place a trusted brand in the subdomain, path, or parameters.

Country-code and multi-part public suffixes can make parsing less obvious. When uncertain, use the organization’s official app or locate its site independently instead of trying to approve the address by inspection alone.

Common tricks in fake URLs

  • Misspellings omit, repeat, or swap letters.
  • Added words such as “secure,” “verify,” “support,” or a location appear beside the brand.
  • Misleading subdomains place the brand before the real domain.
  • Look-alike characters use a lowercase “l,” capital “I,” or characters from another alphabet to resemble the expected spelling.
  • Unrelated shortened links hide the final destination behind a redirect.
  • Long paths and parameters use trusted words to distract from the actual domain.
  • Raw IP addresses use numbers instead of the organization’s normal domain.
  • Unexpected top-level domains end differently from the known site.

An unfamiliar top-level domain is not automatically fraudulent. Common endings such as .com and .org do not prove ownership. Only verified U.S. government organizations can register and operate a .gov domain, but you must still identify the actual registrable domain and evaluate whether the requested action is appropriate.

Does HTTPS make a URL legitimate?

No. HTTPS means the browser can encrypt the connection to the destination named in the certificate. A phishing operator can also encrypt a fraudulent site. The padlock answers whether the connection is protected from ordinary interception; it does not confirm the business, sender, offer, or requested action.

Treat a browser certificate warning as a reason to stop. Treat the absence of a warning as only one technical check.

How to inspect a URL without opening it

On a computer, hover over a link and read the destination shown by the browser or email client. On a phone, press and hold the link to preview or copy it, taking care not to tap the open action. Compare the exact domain with a bookmark, official app, statement, or address you type yourself.

For a button or linked text, the visible words can differ from the destination. A message may display example.com while the underlying link goes elsewhere.

The URL Checker can analyze a copied address for some known malicious signals. Do not enter private tokens, password-reset URLs, or links containing personal account information into a third-party checker.

Evaluate the message as well as the address

A legitimate site can appear in a fraudulent story, and a compromised account can send links from a real service. Before acting, ask:

  1. Did you expect the message and task?
  2. Does the account show the same event when opened independently?
  3. Is the page asking for information or action appropriate to that event?
  4. Is there a safer way to complete the task in the official app?

A clean technical scan cannot verify a seller, job offer, caller, payment request, or document sender.

What to do when a URL looks fake

Do not open it. Preserve the message or screenshot if reporting may be necessary, then use the platform’s phishing or junk-reporting function. Contact the impersonated organization through its official fraud or security channel. Report consumer fraud at ReportFraud.ftc.gov.

If you already opened the destination, follow what to do if you clicked a fake link. The required response depends on whether you entered credentials, paid, downloaded software, or granted a permission.

PSafe’s analysis of fake URLs

Check where the link goes, how it reached you, and what it asks you to do. A plausible domain does not verify the message or request. Scammers can use legitimate cloud-storage and form services to host deceptive content or support a false payment story.

Frequently asked questions about fake URLs

Can a URL contain the real brand name and still be fake?

Yes. Anyone who controls a domain can put brand words in its subdomain, path, or page content. Identify the registrable domain.

Can a link destination differ from the text shown?

Yes. Hyperlinked text and buttons can point to a different address. Preview the destination before opening it.

Is a shortened URL fake?

Not automatically. It hides the destination, which removes information you would otherwise inspect. Expand or verify it before opening when the source or task is uncertain.

Is private-browsing mode safer for suspicious links?

It limits some local history and cookie use. It does not prevent phishing, malicious downloads, tracking by the destination, or voluntary disclosure of information.

Does dfndr security guarantee that a URL is official?

No. URL analysis can identify some known risks. It does not establish ownership, sender identity, or the legitimacy of a transaction.