Fake Microsoft 365 and Google login pages: how to tell

A work email password opens more doors than almost anything else, so fake Microsoft 365 and Google sign-in pages are the most copied pages on the internet. They can look pixel perfect. The address never can.

Updated 24 September 2026 · 5 min read

The short version

  • The logo and the layout prove nothing. Only the address does.
  • Microsoft sign-in lives on login.microsoftonline.com and login.live.com; Google sign-in on accounts.google.com.
  • A password manager that does not offer to fill in your password is a strong warning sign.
  • Some fake pages pass your two-step code through in real time, so a code alone does not make you safe.

How the trick works

The email says a document was shared with you, a voicemail is waiting, your mailbox is full, or your password expires today. The link opens a page that looks exactly like your usual sign-in. It often already shows your email address, which makes it feel real. Whatever you type goes to the attacker.

The page is often hosted on a real service, such as a form builder, a file-sharing site or a cloud storage bucket, so the site itself has a clean reputation. What gives it away is that a Microsoft or Google password is being asked for on an address that does not belong to Microsoft or Google.

How to tell

  1. Check the address bar

    Microsoft 365 and Outlook sign-in happens on login.microsoftonline.com or login.live.com. Google sign-in happens on accounts.google.com. Anything else asking for that password is fake, however it looks.

  2. Watch your password manager

    A password manager fills passwords only on the real domain. If it suddenly offers nothing on a page that looks like your usual sign-in, trust the manager, not your eyes.

  3. Ask why you are signing in at all

    If you were already signed in and a link to a shared file asks you to sign in again, be suspicious. Open the file from your own OneDrive, SharePoint or Google Drive instead.

  4. Scan the link

    Paste the link into the scan box below. Dralvia flags a sign-in form on an address that does not belong to the brand it copies, and shows the evidence.

Why two-step sign-in is not always enough

Some phishing kits sit between you and the real sign-in page. They pass your password and your code to the real service in real time and keep the session they get back. A code by text or an app approval does not stop that. Passkeys and security keys do, because they only work on the real domain.

If you typed your password into one of these pages, change it now and sign out all sessions. The steps are in I clicked a phishing link: what to do now.

Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.

Live product launcher
Paste a suspicious URL or domain, then continue in the live platform

Questions people ask

The page already showed my email address. Doesn't that mean it is real?
No. The attacker put your address into the link they sent you, so the page can display it. It proves they know your email, nothing more.
What should IT teams do?
Move staff to passkeys or security keys where possible, make reporting a suspicious email one click, and check sign-in logs for new sessions after anyone reports that they typed a password.