Fake Login Pages: How They Copy the Real Thing
Phishing login pages can look pixel-perfect and even relay your two-step code in real time. How fake sign-in pages work and the signs that reveal them.

The goal of most phishing is a fake login page. It copies the real sign-in screen of your email, bank or work account, down to the logo and fonts. Modern phishing kits go further: they pass your details to the real site in real time, so you may even appear to log in successfully.
How fake login pages work
- Cloning: the real page's design is copied exactly.
- Pre-filling: your email address is included in the link, so the page greets you by name.
- Relaying: "adversary-in-the-middle" kits forward your password and two-step code to the real site, capturing your session.
- Redirecting: after you enter details, you are sent to the real site so nothing seems wrong.
- Hosting: pages sit on lookalike domains or on legitimate cloud services. See cloud storage links.
Signs you are on a fake page
- The domain is not the service's real domain. See how to read a URL.
- Your password manager does not offer to fill in. See password managers as a phishing alarm.
- You arrived from a link in an email, text or ad.
- You are asked to sign in when you should already be signed in.
- After signing in, you are sent back to the start or shown an error.
Text codes and app approvals can be relayed. Passkeys and security keys only work on the real site, so fake pages cannot use them. See passkeys vs phishing.
If you entered details
Change the password immediately from the real site, sign out of all sessions, and check for new devices and forwarding rules. See entered your password on a phishing page.
Unsure about a sign-in page? Paste its address into CyberWatch AI Scan for a free check.
For more, read our phishing guide.
Frequently asked questions
Can a fake login page steal my two-step code?
Yes. Some phishing kits relay your password and code to the real site in real time, logging the attacker in. Passkeys and security keys resist this.
The page even showed my email address. Is it real?
Not necessarily. Phishing links often include your email address so the fake page can pre-fill it.
What is the quickest tell?
The web address, and your password manager not offering to fill in your password.
Sources
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Report a phishing page, Google Safe Browsing


