How to spot a fake exchange: the tell isn't on the page, it's in that one line of URL
A clone site can copy Binance's interface, fonts, and buttons wholesale — the eye can barely tell them apart. But there's one thing it can't copy: the URL. Learn to read that line character by character, and build the habit of entering through a bookmark, and most of these deposit scams never make it through the door.
A lot of people assume a fake site will have "tells" — a broken layout, an odd font, something that looks fake at a glance. In reality, today's clone sites can mirror the official site page for page, even simulating the dashboard you see after logging in. So judging by "does it look right" is no longer enough; you need a harder method.
What a clone site looks like
A clone site's method is straightforward: copy the official site's HTML, images, and styles wholesale and host them on a domain the scammer controls. The logo, colours, login box, and price charts you see are all the real assets, which is why it looks right. The only difference is that once the form is submitted, your username and password land in the scammer's database.
Some clone sites go further and act as a "man in the middle": the username and password you enter are relayed in real time to the real official site to log you in, 2FA one-time code and all — so you "really do log in successfully", with nothing seeming off. But the whole process happens on the scammer's page; they can see everything and can take over your session. That's why "I logged in and it looked normal" cannot be taken as proof of safety.
There's a mindset to flip here: many people judge a site's authenticity by "does it look right", "is it laggy", "can I log in". But these clone sites can make the screen identical and the login smooth, so none of those is reliable. The only thing that won't lie is the URL line. The screen is what you're shown; the URL is the real location of the server you're connecting to. Shifting your judgement from "how it looks" to "what the URL is" is step one in spotting a fake site.
The five phishing-domain tactics
However real a clone site looks, it still has to sit on a URL, and that URL can't be exactly the same as the official one. The scammer's effort all goes into making the URL "look similar". Common tactics:
1. Swapped letters (typosquatting)
Nudge the official spelling by a letter or two, betting you won't look closely: binance becomes binnance, blnance, bínance, bynance. A quick glance slides right past it.
2. Look-alike characters (homoglyphs)
Replace a character with one that looks like it — lowercase l for the number 1, the letter O for the number 0, even letters from other scripts that look identical mixed in. Visually almost the same; in reality a completely different URL.
3. Junk subdomains
Stuff the official word into a subdomain, for example binance.login-secure.com. It starts with binance, but what really decides which site it belongs to is the rightmost segment — here the real domain is login-secure.com, which has nothing to do with Binance.
4. The wrong TLD (ending)
Swap out the common official ending, for example replacing .com with some rare country-code or newer ending. The main part is spelled right, the ending is wrong, and it's still someone else's site.
5. Official words up front, the real domain buried behind
For example binance-verify.xyz or binance-tw-support.net. The word you recognise is placed up front where it's most visible, but the real domain body and ending are its identity — and your eyes were already soothed by the front part.
How to read a URL the right way
Here's a fixed routine, the same every time:
- Ignore the https prefix and the path (the slash-separated stuff at the end); they don't tell you which site it belongs to.
- Reading left to right, find the first standalone slash "/"; everything before that slash is the domain.
- Within that domain, look at the rightmost two segments (main domain + ending), for example example.com. Whether those two are right decides everything.
- Compare the main domain spelling character by character, watching especially for the easy mix-ups l / 1 and O / 0, and any extra or missing letters.
If you're not confident comparing by eye, drop the whole URL into the look-alike domain checker; it compares against the official domain character by character and flags suspicious differences. The padlock icon (https) only means the connection is encrypted, it doesn't mean the site is real — a fake site can have a padlock too, so don't treat it as a safety guarantee.
Look-alike characters are the hardest to catch by eye, because two characters look almost identical and differ only in their encoding. When a URL looks fine but you can't quite say why it feels off, rather than squinting at the screen, just hand it to a tool for a character-by-character check. Keep one mindset: judging a URL shouldn't rest on "I think it's right", it should rest on "I compared it". When you're rushed or anxious, your eyes are most likely to let things slide — and that's exactly the state a phishing link wants you in.
How you ended up on the fake site
Most people weren't dragged to a fake site; they walked in themselves. The most common entry points:
- Search-engine ad slots: search "Binance login" or "Binance official site" and the top result marked "Ad / Sponsored" may be a fake site that bought the keyword. People habitually click the first one — right into the trap.
- Chat messages and community links: links from fake support, groups, and DMs, dressed up as "log in to claim a reward" or "verify your account".
- Buttons in emails: a convincing "Binance" email with a "log in now" button pointing to a phishing page. See the fake email entry.
- QR codes: a QR code on a poster, a post, even at a fake event — scan it and you're on a fake site.
See the common thread? The problem is always the entrance. As long as you don't go in through these entrances other people hand you, no fake site, however convincing, can reach you.
The bookmark-login rule
The easiest and most reliable move against fake sites is to do the URL-judging "once, so you never have to again":
- Confirm the official URL once using the method above.
- Add it to your browser bookmarks.
- From then on, log in through the bookmark every single time — no more search, no more clicking links anyone sends you.
The benefit of this rule is that once you've confirmed it in a "clean state", you won't get ambushed by a phishing link in some rushed, frazzled moment later. Same on a phone — add the official app or site to your home screen and go in through a fixed entrance. For the fuller setup and common pitfalls, see the bookmark-login rule.
A warning about a habit that quietly defeats it: many people do add the bookmark, but when they suddenly need to log in they still type "Binance login" into the search box out of reflex, because it's "faster". That small move renders the bookmark useless. Treat it like "use your own key at your front door, don't pick up a key off the ground" — however rushed, go in through the bookmark. Also, build the bookmark at the moment you've confirmed the official site is correct; don't save a page you reached from a suspicious link as a bookmark, or what you've saved is a fake entrance.
Pre-deposit checklist
Before you deposit or place an order, spend ten seconds running through this — it beats regret later:
- Did you come in from a bookmark / the official app? If not, back out and re-enter from the bookmark.
- Are the rightmost two segments of the URL correct? Read the main domain and ending character by character, using the domain checker if needed.
- Anything off about the login flow? A sudden extra request for a seed phrase or private key, or being told to "transfer to some address first to verify", are all signs of a fake site — stop immediately.
- Are you being rushed? Pages paired with "limited time", "limited spots", or "your account will be frozen if you don't deposit" automatically lose credibility.
- Is 2FA normal? A real-site login goes through the 2FA flow you're familiar with; a flow that's odd or asks you to turn 2FA off is a danger signal.
Make this list a fixed pre-deposit routine and a fake exchange basically never gets a chance at your money. For the full picture of related tactics, see the 2026 Binance scam round-up.
The list looks long, but once you've run it a few times it takes under ten seconds, and most of the time you only need to confirm the first item — "did I come in from the bookmark". That's why fixing the entrance matters so much: when the entrance is reliable, the rest of the checks are mostly a quick confirmation, not white-knuckle vigilance every time. The truly dangerous scenario is "switched devices on the fly, rushing to deal with something, searched and clicked on impulse" — because that's when you skip every check. So rather than demanding constant alertness of yourself, make "only go in through a fixed entrance" a habit you don't have to think about — a habit blocks fake sites for you when you're most tired and distracted, which is exactly when people are most likely to slip.
One more common misjudgement to flag: some people relax the moment they see "binance" at the front of the URL, without noticing it's decoration stuffed into a subdomain. Once more: a site's identity is decided by the rightmost two segments (main domain + ending), and no amount of official-looking words in front counts. Moving your eyes to the right, to the ending, is the muscle memory most worth building when reading a URL — that small move blocks a whole big class of phishing domains.
How a clone site is built, and the seams that give it away
It helps to picture how one of these sites is actually put together, because once you know what the scammer can and can't fake, you know exactly where to look. The build is two halves. The first half is the page you see — and it's the easy half. A scammer points a tool at the real exchange, saves the page, and walks away with every image, every stylesheet, the logo, the live-looking charts, even the login box. None of that is hard to copy, because it was all sent to your browser to begin with. So the page can be flawless. Visual perfection proves nothing — it only tells you the scammer knew how to right-click and save. The second half, the part the scammer can't copy, is where the page lives: the URL. That's why every check below comes back to one line of address, never to how the page looks.
The whole con, then, lives in making one wrong address feel like the right one. There are only a handful of ways to do that, and each has a matching way to catch it. Read these as moves and counter-moves, not as a list to memorise.
Swapped letters, betting you skim
The scammer registers a name that's the real one nudged by a letter or two — a doubled consonant (binnance), a swapped vowel, a number standing in for a letter. Your eye reads the shape of a word, not the letters, so binnance slides past at a glance the same way a typo does in your own writing. Catch it: don't read the name as a word, read it as characters, left edge to right edge, and say each one to yourself. The fakes survive on speed; slowing down for two seconds kills most of them.
The ending swapped out (TLD tricks)
The name is spelled perfectly, but the ending is wrong: the real .com becomes .co, .cc, .net, .org, or some cheap newer ending. People check the spelling, see it's right, and never glance at the last few characters. Catch it: the ending is part of the identity, not an afterthought. A name with a different ending is a different site owned by a different person, full stop. Confirm the exact ending the real exchange uses, once, and treat anything else as a stranger wearing the name.
Look-alike letters and the xn-- giveaway
This is the nastiest one, because there's nothing to "spot" — the letters genuinely look the same. Some alphabets contain characters drawn almost identically to Latin ones, so a name can be assembled where one letter is from a different script entirely. On screen it reads as the real name; underneath it's a string your eye has never actually seen. The good news is that browsers defend against this: when a domain uses these mixed characters, the address bar usually rewrites it to a form starting with xn-- (called Punycode). Catch it: if you ever see xn-- at the front of what should be an ordinary English name, that name was built from look-alike characters — leave. And because this one defeats the naked eye by design, it's the case where you stop trusting your eyes and paste the address into the domain checker, which compares the underlying characters, not the picture of them.
Stuffing the real name into a subdomain
Here the official word is real and spelled right, but it's been demoted to a label out front: binance.secure-login.com. Read left to right and you're reassured in the first second. But a URL is owned from the right: the two segments at the end — here secure-login.com — are the actual owner, and everything to the left of them is just rooms inside that owner's house. Catch it: find the last dot before the first slash, take the chunk on either side of it, and that pair is who you're really talking to. The famous name sitting up front is decoration the scammer placed there precisely because that's where your eyes land first.
Extra words and hyphens bolted on
A close cousin: keep the real name but glue something reassuring to it — binance-verify.com, a region code, a word like "secure" or "support". It reads as an official sub-service, but a hyphen doesn't join you to the real company; it just makes a longer name that someone else registered. Catch it: the real name with anything added to it is not the real name. Strip the extras in your head and ask whether what's left, as the rightmost two segments, is exactly the address you confirmed.
Notice that every counter-move lands in the same place: a site's identity is the rightmost two segments — main domain plus ending — and you read them right to left. Front-loaded words, subdomains, hyphens, and dressed-up paths are all noise aimed at the left side of the line, where you start reading and where you're most easily satisfied. Train your eye to jump to the end first and the whole catalogue above collapses into one habit.
Why the padlock fools people
One reassurance deserves dismantling on its own, because it stops people mid-check. The padlock icon and the "https" in front of the address only mean the line between your device and that server is encrypted — that nobody in the middle can read it. It says nothing about who owns the server at the other end. These certificates are free and handed out automatically, so a phishing site gets one in minutes and shows the same padlock the real site does. A padlock on a fake exchange just means your password travels safely into the scammer's database. Treat it as "this connection is private", never as "this site is who it claims to be".
The thirty-second routine before you log in or deposit
Tie it together into something you run on reflex, not a checklist you fish out. Before you type a password or send a single coin:
- Did I arrive from my own bookmark or app? If a search result, a message, or an email brought me here, back out and re-enter from the saved entrance — that one move skips every trick above.
- What are the rightmost two segments? Read the ending and main domain right to left, character by character, and confirm they're exactly the address I saved before.
- Anything starting with xn--, or any feeling I can't name? Hand the URL to the domain checker rather than squint.
- Is the login flow asking for something it never normally does? A real exchange never wants a seed phrase or a "verification transfer" to an address — those requests are the fake site showing its hand.
One last point most guides skip, because it matters even when the login looks clean. The danger isn't only at the password box. A clone — especially the man-in-the-middle kind that relays you into the real site — can sit between you and your account during a withdrawal and quietly swap the destination address for the scammer's. You think you're sending to your own wallet or to a friend; the page shows what you expect; the coins land somewhere else. So the same address-reading discipline applies on the way out as on the way in: before you confirm a withdrawal, check the destination address character by character against your own record, not against what the page conveniently filled in. The entrance you trust gets you safely onto the site; this last check makes sure the exit is yours too.
When we judge whether a URL is real, we've never gone by "does it look right" — we compare it against the official one character by character, which is exactly what this site's domain checker does: it lines up the main domain and ending of what you enter against the official one and flags even a single swapped letter or changed ending, the differences the eye slides past most easily. Doing the comparison, you notice the scammer's effort almost always goes into "the front looks similar", while the giveaway sits in the rightmost two segments. It only does a string-level check — it's there to help you see clearly, not to replace your habit of entering from a bookmark.
What you should truly turn into muscle memory are these three columns: one, whether the rightmost two segments of the domain (main domain + ending) match exactly — that's the site's real identity; two, whether an extra subdomain is putting official words up front to soothe your eyes; three, whether the login process throws up an "enter your seed phrase / private key" or "transfer first to verify" step that no official process has — if one appears, back out.
FAQ
There's a green padlock and it's https. Does that mean it's safe?
No. The padlock only means the connection between you and the site is encrypted; it doesn't mean the site is official. A phishing site can get an encryption certificate easily and still show a padlock. The test is the domain itself, not the padlock.
I already entered my username and password on a fake site. What do I do?
Immediately go to the real official site (via your bookmark), change your password, reset or re-bind your 2FA, and check whether your withdrawal whitelist and API keys have been tampered with; freeze the account and withdrawals if needed. The faster the better, ahead of the other side. For what to do next, see the first 4 things to do after a scam.
How do I see the full URL on a phone?
A phone address bar often shows only part of the URL; tap it to expand the full view, or simply don't log in through the browser and use the official app instead. Download the official app from the official site link, put it on your home screen, and going in through a fixed entrance is most reliable.