Destination identity
Read the hostname from right to left
The registered domain is the core identity. A familiar word placed in a subdomain or path does not control the destination. Look at the final registered name before the first slash, then compare spelling, hyphens, numbers and top-level domain with an earlier trusted record.
HTTPS protects the connection to the destination; it does not prove that the destination belongs to the expected operator. A copied site can also obtain a valid certificate. Treat HTTPS as one technical requirement, not an ownership certificate.
Redirect chains deserve attention. If a login action moves through several unrelated hostnames, record each one. A service may legitimately use multiple systems, but the relationship should be explainable and consistent—not a different destination on every visit.
Stronger identity signals
- Stable links inside an existing trusted account
- Consistent package and destination relationship
- Support details that remain unchanged across trusted records
- Payment instructions that match the current transaction context
- Clear terms and contact information before sensitive actions
