Suppose you receive a message saying your SBI account requires verification. The link looks official at first glance because it contains words you recognize.
Suspicious link example
Message: Your SBI account requires verification.Link: https://sbi.co.in.login-secure.comAt first glance, you see: sbi.co.inActual website: login-secure.comRead the Real Domain
The Simple Trick
Read the important part of the domain from right to left. The real website owner is usually the main domain near the end of the hostname, before the final extension.
Safe vs suspicious
payments.amazon.in -> actual domain: amazon.inamazon.in.payment-update.com -> actual domain: payment-update.comIn the second example, the words amazon.in appear in the link, but they are being used to fool you. The actual domain belongs to payment-update.com.
Another Example
Google-style example
Safe-looking: accounts.google.com -> main domain: google.comSuspicious: google.com.verify-account.net -> main domain: verify-account.netScammers know that people scan links quickly, especially on phones. They place trusted company names at the start of the link, hoping you will not read the full domain.
Scammers Also Use Lookalike Names
Lookalike domains
arnazon.com instead of amazon.compaypa1.com instead of paypal.comSmall differences are easy to miss on a phone. A lowercase L, the number 1, or letters that look similar can make a fake site feel real for a moment.
Before Logging In or Paying
Look carefully at the domain and ask: who actually owns the website I am on? Do not trust a URL simply because your bank, Amazon, Google, or another company name appears somewhere inside it.
Remember
Read the domain, then trust. A familiar company name inside a link is not enough.
Series
Internet Security Basics: 10-Part Series for Everyday UsersA 10-part series for everyday users to identify scams, protect accounts, and use the internet with more confidence.
Is This Email Really From Your Bank or Company?
Check sender names, email addresses, and urgent payment messages before trusting them.
Can You Spot the Real Website?
Learn how fake domains, confusing links, and lookalike names trick everyday users.
HTTPS Does NOT Mean the Website Is Genuine
Understand what the lock symbol protects, and why you still need to verify the domain.
Does a Professional Domain Extension Mean the Website Is Genuine?
Learn why .com, .org, .in, .net, and .ai do not automatically prove trust.
The Link Says SBI, But Where Does It Actually Go?
Learn why visible link text and button labels can hide a completely different destination.
Sir, Please Tell Me the OTP for Verification
Learn why OTPs, passwords, UPI PINs, recovery codes, and remote access must stay private.
Scan This QR Code to Receive Your Refund
Learn how QR codes can hide payment requests, fake links, and UPI PIN traps.
Someone Sent You BankKYC.apk on WhatsApp. Should You Install It?
Learn why APKs, cracked software, and fake apps can hide malware or dangerous permissions.
Which Airport Wi-Fi Is the Real One?
Learn how fake public Wi-Fi names and captive portals can trick users into unsafe logins.
Before You Click, Pay or Login, Take 30 Seconds
Use a quick checklist before reacting to urgent messages, links, payments, or login prompts.
Nikhlesh Yadav is a Technical Lead and Solution Architect with 12+ years of experience across cloud-native systems, distributed platforms, AI integrations, Web3, and cyber security.
Read full profile