Fake Microsoft 365 and Google login pages: how to tell
A work email password opens more doors than almost anything else, so fake Microsoft 365 and Google sign-in pages are the most copied pages on the internet. They can look pixel perfect. The address never can.
The short version
- The logo and the layout prove nothing. Only the address does.
- Microsoft sign-in lives on login.microsoftonline.com and login.live.com; Google sign-in on accounts.google.com.
- A password manager that does not offer to fill in your password is a strong warning sign.
- Some fake pages pass your two-step code through in real time, so a code alone does not make you safe.
How the trick works
The email says a document was shared with you, a voicemail is waiting, your mailbox is full, or your password expires today. The link opens a page that looks exactly like your usual sign-in. It often already shows your email address, which makes it feel real. Whatever you type goes to the attacker.
The page is often hosted on a real service, such as a form builder, a file-sharing site or a cloud storage bucket, so the site itself has a clean reputation. What gives it away is that a Microsoft or Google password is being asked for on an address that does not belong to Microsoft or Google.
How to tell
Check the address bar
Microsoft 365 and Outlook sign-in happens on login.microsoftonline.com or login.live.com. Google sign-in happens on accounts.google.com. Anything else asking for that password is fake, however it looks.
Watch your password manager
A password manager fills passwords only on the real domain. If it suddenly offers nothing on a page that looks like your usual sign-in, trust the manager, not your eyes.
Ask why you are signing in at all
If you were already signed in and a link to a shared file asks you to sign in again, be suspicious. Open the file from your own OneDrive, SharePoint or Google Drive instead.
Scan the link
Paste the link into the scan box below. Dralvia flags a sign-in form on an address that does not belong to the brand it copies, and shows the evidence.
Why two-step sign-in is not always enough
Some phishing kits sit between you and the real sign-in page. They pass your password and your code to the real service in real time and keep the session they get back. A code by text or an app approval does not stop that. Passkeys and security keys do, because they only work on the real domain.
If you typed your password into one of these pages, change it now and sign out all sessions. The steps are in I clicked a phishing link: what to do now.
Check a link now, free
Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.
Questions people ask
- The page already showed my email address. Doesn't that mean it is real?
- No. The attacker put your address into the link they sent you, so the page can display it. It proves they know your email, nothing more.
- What should IT teams do?
- Move staff to passkeys or security keys where possible, make reporting a suspicious email one click, and check sign-in logs for new sessions after anyone reports that they typed a password.
More guides
A 30-second checklist for suspicious emails: the real sender, the pressure, the links, the attachments and the request. Plus what to do when you find one.
Clicked a phishing link or typed your password into a fake page? The steps to take right now, depending on what happened, in the order that limits the damage.
The few settings that stop most account takeovers: a password manager, unique passwords, passkeys or two-step sign-in, and checking your recovery details.