How to Read a URL Like a Security Analyst
Security analysts read web addresses in a particular order to find who really owns a link. How to break down any URL into its parts and spot the tricks phishers use.

A web address can look intimidating, but it has a simple structure. Once you know which part identifies the owner, most phishing links give themselves away. Here is how security analysts read a URL.
The parts of a URL
| Part | In the example | Meaning |
|---|---|---|
| Scheme | https:// | Encrypted connection. Says nothing about honesty. |
| Subdomain | login. | Chosen freely by the domain owner. |
| Registered domain | examplebank.com | Who controls the site. |
| Path | /account/verify | A page on the site. Can contain any words. |
| Query | ?id=123 | Extra data. Ignore for ownership. |
The method
- Find the first single slash after "https://". Ignore everything after it.
- Read the host name from right to left: start with the ending (.com, .co.uk), then the word before it. That pair is the registered domain.
- Ask: is that the organization's real domain?
Applying it to tricks
| URL (illustrative) | Registered domain | Owner |
|---|---|---|
| examplebank.com.verify-login[.]net/secure | verify-login.net | Not the bank |
| secure-examplebank[.]com | secure-examplebank.com | Not the bank |
| login-check[.]info/examplebank.com | login-check.info | Not the bank |
| examplebank.com/help | examplebank.com | The bank, if this is its real domain |
Other things analysts notice
- Lookalike characters and swapped letters. See lookalike domains.
- An "@" sign in the address, which can hide the real destination.
- Shortened links that hide the destination. See shortened links.
- Unusual endings for a brand you know.
Want a second opinion on a link? Paste it into CyberWatch AI Scan for a free check. For everyday steps, see checking a link without clicking.
For more, read our phishing guide.
Frequently asked questions
What is the most important part of a URL?
The registered domain: the name just before the ending (such as .com or .co.uk), immediately before the first single slash. It tells you who controls the site.
Why read right to left?
Because the domain owner is at the right-hand end of the host name. Everything to the left of it can be chosen freely by that owner.
What about the part after the slash?
The path can contain anything, including real brand names, and does not affect who owns the site.
Sources
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
- Report a phishing page, Google Safe Browsing


