One of the most effective tricks criminals use is creating a fake login page that looks exactly like the real thing. You click a link in an email, a search result or a message, and you land on what appears to be the Microsoft sign-in page, your bank's website or your email provider's login screen. You enter your username and password, and they now have your credentials.
These pages can be almost impossible to distinguish from the real thing by appearance alone. But there are a few things you can check before you type anything.
Check the URL first, every time
This is the single most important habit. Before entering any login details, look at the address bar at the top of your browser.
A real Microsoft login page will show login.microsoftonline.com or login.live.com. A fake one might show something like login-microsoft365.com, microsoftonline-secure.net, or a long string of random characters. The domain is the part right before the first forward slash. Everything else can be made to look legitimate.
If the URL looks even slightly wrong, do not enter your password. Close the tab immediately.
Be suspicious of how you got there
Think about what brought you to this login page. Did you click a link in an email? Did a pop-up ask you to sign in again? Did a search result take you somewhere unexpected?
Legitimate services rarely send you emails asking you to click a link and sign in urgently. If you received an email saying your account is at risk, your mailbox is full or your password is expiring, do not click the link. Instead, open your browser and go to the service directly by typing the address yourself.
Look for small visual clues
Fake login pages are getting better all the time, but they often have small giveaways. The logo might be slightly blurry or outdated. The page might be missing elements you normally see, like a footer or language selector. There might be spelling mistakes in the text around the login form.
None of these are guaranteed indicators on their own, but combined with a suspicious URL or an unexpected email, they should raise your alert level.
Check for HTTPS but do not rely on it
A padlock icon in the address bar means the connection is encrypted. It does not mean the website is legitimate. Criminals can get security certificates for fake websites just as easily as anyone else. The padlock tells you the connection is secure, not that the website is trustworthy.
Always check the actual domain name, not just the padlock.
Use a password manager
One underrated benefit of using a password manager is that it will not autofill your credentials on a fake website. Password managers match the saved login to the exact domain. If you land on a fake Microsoft page, your password manager will not offer to fill in your details because the domain does not match. If your password manager does not recognise the page, treat that as a warning sign.
If you need a strong, unique password for your accounts, use our free password generator to create one.
What to do if you entered your details on a fake page
If you think you may have entered your password on a fake login page, act immediately. Change your password on the real site straight away. If you use the same password anywhere else, change it there too. Enable multi-factor authentication if it is not already turned on. Then contact your IT provider so they can check for any unauthorised access to your account.
When to get help
If you are not sure whether a login page is real, do not take the risk. Close the browser and contact your IT provider. It is always better to ask than to hand over your credentials. Recloud helps businesses train their staff to recognise these attacks and puts technical controls in place to block fake login pages before they reach your team.