The old advice for spotting phishing, "look for the padlock and spelling mistakes", no longer works. Most phishing pages use HTTPS, AI tools write fluent text and page kits copy real login screens pixel for pixel.

Effective detection, whether by a person, a browser extension or a research system, combines several independent signals. No single signal is reliable on its own; together they are.

Signal 1: The URL and domain

  • Look-alike domains – swapped letters, extra words or different top-level domains (paypa1-secure.com, microsoft-login.support).
  • Brand in the wrong place – login.microsoft.com.example.net belongs to example.net.
  • Domain age – newly registered domains are much more likely to be malicious.
  • Unusual hosting – login pages served from free hosting, file-sharing or form-builder services.

Signal 2: Page content and behaviour

  • A login form for a brand that does not match the domain.
  • Forms that send credentials to a different domain from the one you are on.
  • Heavy obfuscated JavaScript, disabled right-click, or content loaded only after a delay to avoid scanners.

Signal 3: Language and intent

Phishing relies on pressure. Look for urgency ("account suspended in 24 hours"), fear, unexpected rewards and requests for credentials, payment or codes. Language models are useful here, because they can judge intent even when the text is fluent.

Signal 4: Visual similarity

A page that looks like a known brand's login but is not hosted on that brand's domains is a strong signal. Comparing screenshots against known brand pages catches kits that change their text and code to evade other checks.

Combining signals

Each signal alone produces false positives. A new domain is not always malicious, and many legitimate pages are urgent. Combining signals and weighing them gives far better accuracy.

text
URL risk (look-alike, new domain)   ─┐
Content risk (cross-domain form)    ─┼─► combined assessment ─► explained warning
Language risk (urgency, credentials)─┤
Visual risk (brand look-alike)      ─┘

Explain the warning

A warning is only useful if people trust it. "This page looks like Microsoft's login but is hosted on a domain registered 3 days ago" is far more convincing than "Dangerous site". Explainable warnings help users make the right decision and learn to spot the next attempt.

Practical protection

  • Use a password manager: it will not autofill on a look-alike domain.
  • Prefer passkeys, which cannot be phished to another domain.
  • Navigate to important sites directly rather than through links in messages.

Key takeaways

  • HTTPS and good grammar no longer indicate a safe site.
  • Combine URL, content, language and visual signals.
  • Explained warnings are more effective than generic ones.
  • Password managers and passkeys provide strong built-in protection.