How to Tell If a Website Is Safe on iPhone

Practical checks for spotting phishing and lookalike sites on iPhone — reading a domain correctly, the signals that mean nothing, and what actually helps.

Updated August 2026

Quick answer

Read the domain from the right-hand end, not the left: the real site is the last two parts before the first slash. `apple.com.login-verify.co` is `login-verify.co`, not Apple. A padlock proves encryption, not honesty — phishing sites have padlocks too. The strongest signals of trouble are an unexpected link, urgency about your account, and a domain that is nearly-but-not-quite right.

Read the domain from the right

Almost every convincing phishing URL exploits the same habit: people read left to right and stop once they see a familiar brand. Browsers do the opposite — what matters is the registered domain, which sits at the right-hand end, immediately before the first single slash.

URLActual siteVerdict
apple.com.login-verify.co/idlogin-verify.coNot Apple
secure-paypal.com/loginsecure-paypal.comNot PayPal
appleid.apple.com/sign-inapple.comGenuine
icloud.com.security-check.netsecurity-check.netNot Apple

Everything to the left of the real domain is chosen freely by whoever owns it. A subdomain can say literally anything.

On a phone this is materially harder than on a desktop, because the address bar truncates. Tapping the bar to see the full URL before acting is worth the two seconds.

Lookalike domains and typo-squatting

The second family of attacks registers a domain that reads as correct at a glance:

  • Swapped characters that look alike — `rn` for `m`, `1` for `l`, `0` for `o`
  • A different ending — `.co`, `.net`, or `.shop` in place of `.com`
  • An extra or missing hyphen, which most people never notice
  • Plausible extra words — `-secure`, `-login`, `-support`, `-billing`

These are called typo-squatting or lookalike domains, and they are effective because nothing about the page is wrong. The design is copied pixel-for-pixel, the padlock is real, and the certificate is valid — because the attacker genuinely owns that domain.

Which signals actually mean something

SignalWhat it proves
Padlock / HTTPSThe connection is encrypted. Nothing about who is on the other end.
Professional designNothing. Phishing pages are copied from the real site.
Arrived via a link you did not expectMeaningful — most phishing starts here.
Urgency about your accountMeaningful — pressure is the mechanism, not a side effect.
Domain nearly rightStrong signal. Genuine companies do not log you in from a variant domain.
Asks you to re-enter a password after you are signed inStrong signal.

How Avodek helps

Avodek checks each page before it opens and warns on known phishing sites and on lookalike, typo-squatted domains — the category that is hardest to catch by eye on a small screen. It also flags risky downloads, warning on file types like executables and archives before they land.

None of that removes the need to read the domain. Reputation checks lag behind newly registered domains by design, and a phishing site's most dangerous hours are its first few. Treat the warning as a backstop, not the primary defence.

Common questions

Does the padlock mean a site is safe?

No. It means the connection is encrypted. Certificates are free and issued automatically, so phishing sites have padlocks as a matter of course. It proves privacy in transit, not honesty at the other end.

How can a fake site look exactly like the real one?

Because it usually is the real one, copied. Pages are public — an attacker downloads the markup, styling, and images and serves them from their own domain. Visual fidelity costs nothing.

What should I do if I already entered my password?

Change that password immediately, starting with any other account using the same one, and turn on two-factor authentication if it is not already on. If card details were entered, contact your bank. Speed matters more than certainty here.

Are links in text messages more dangerous than in email?

They are harder to judge rather than inherently worse: there is no sender name to inspect, link previews are shortened, and messages carry an assumption of familiarity. The same rule applies — reach the site yourself rather than through the link.

Related guides

Get Avodek

Private Browser + AI · Free on the App Store.

Learn more about Avodek