Login check
How to spot a fake login page: the web address always gives it away
The page looks exactly the same: the same logo, the same colours, the same form. That is not a coincidence. The Dutch Fraud Helpdesk warns that websites of companies and organisations are copied very well, and says plainly: "Daardoor kunt u niet zien dat ze nep zijn" — you cannot see from the page that it is fake (Fraudehelpdesk). That leaves one part the copy cannot hide: the web address in your address bar.
The rule that breaks the pattern: you enter credentials only on an address you typed yourself or opened in your own app — never on a page you reached through a link, a message or a QR code.
Direct answer: five checks before you log in
- Open the service yourself, not the link. Type the address you already know, or use your bookmark or the bank's app. A link in a message is someone else's route; your own route removes the question of whether the link is right.
- Read the domain, not the rest of the URL. Everything before the first slash is the address; anything after it can say whatever it likes. Compare character by character: an extra word, a hyphen where a dot belongs, a different spelling or a different extension means you are not on that organisation's site. If you doubt a link, check it with a link checker instead of clicking it (veiliginternetten.nl, ScamCheck).
- Let your password manager refuse the form. It only fills on the domain you saved earlier. An empty field on a page you never visited yourself is a signal, not a convenience.
- Expecting a message? Go to your own environment. Governments and most banks place messages in your own app or message box, not behind a link. The Dutch digital ID says it without qualification: "DigiD stuurt u nooit berichten met een link of QR-code" — DigiD never sends messages with a link or QR code (DigiD). What is not in your own environment was not sent.
- Never enter data on a page you reached through a code or link. Not even when the page looks perfect, names the right organisation or applies time pressure. Do not click and do not scan, and close the page (DigiD).
Why the design proves nothing
A copy takes a minute: the form is lifted one-to-one from the real site. Logos, menus and even error messages then match. Only the address is tied to whoever actually runs the site, which is why the clue sits in the address bar and not in the layout.
What a detector does and does not see
Of a suspect page you usually have a screenshot, sometimes the text. You can run that image through the image detector and retyped text through the text detector as triage: it helps decide which message to verify first. It says nothing about the page. A fake page is often an exact copy of the real one and therefore scores low, while a genuine page can pick up a signal from compression or editing. The score tells you nothing about the sender and nothing about authenticity.
What a login page cannot tell you
- whether the page is really run by that bank, authority or platform;
- whether the form sends your data to the right party; only the domain shows that;
- whether the request to log in makes sense at all — companies rarely ask this unannounced through a message;
- whether this is fraud; only a bank or the police establish that.
So treat the page as a trigger for your own route, not as proof that something is wrong with your account.
If you already logged in
- Change the password of that account straight away, and of every account that shares it.
- Was it your digital ID or a government login? Follow the steps for fraud or misuse of your DigiD: block it, request a new one where needed, and contact the national fraud desk (DigiD).
- Did you enter card details or codes? Call your bank on a number you found yourself and have the account or card blocked (DigiD).
- Keep the evidence: the message, the link, the page and the time. A message you kept can go to the organisation involved so the copy is taken down (DigiD).
More checks are in the guides on spotting a fake QR code, a fake tax authority message and a fake bank call. To check a message or a file on its own, use the free checker.
Frequently asked questions
The page looks exactly like the real one. How can it be fake?
Because the design is easy to copy. The Fraud Helpdesk states that the copies are so good that you cannot tell from the page itself that it is fake; the check therefore sits in the address you type yourself (Fraudehelpdesk).
There is a padlock and https in the address bar. Is it safe then?
An encrypted connection means your connection to the page cannot be eavesdropped on; it says nothing about who runs the page. A copy can be encrypted too. Look at the domain, not the padlock.
Does a detector score prove a login page is fake?
No. The score describes patterns in a text or a file and says nothing about the sender. A copy can score low precisely because it was taken over exactly, and a genuine page can pick up a signal from compression.
