Security, Abuse & Privacy

Phishing Page

Definition

A phishing page pretends to belong to a bank, an employer, a delivery company or a well-known service, and its purpose is to collect something the visitor would only give to the real one. It is a category a host must recognise and refuse, not a technique this page describes. What matters for anyone publishing legitimately is the boundary: impersonation of a real brand plus a field asking for a credential is the combination that gets content removed, and it does not need to be malicious to look that way. Design mockups, security training materials and template login screens can all sit close to that line. Hosts publish their rules on this in an acceptable use policy and enforce them through scanning and reports.

Why It Matters

The consequences do not stop at the page. Browser safe-browsing services and mail providers blocklist by hostname and sometimes by parent domain, so one phishing page on a shared domain can throw a full-screen red warning in front of every unrelated site under it, and those listings can take days to clear after the content is gone. That is why free hosts act fast and ask questions afterwards. For the legitimate publisher it means two practical things: expect anything that resembles a branded sign-in screen to be reviewed, and expect the review to go faster if the content says plainly what it is. A mockup labelled as a mockup, with no working input field, rarely causes trouble.

How It Works

Detection combines several signals. Page text and layout are compared against the brands most commonly impersonated; the presence of a credential or payment field on a page carrying another company's name and marks raises the score sharply; hostnames that borrow a well-known brand name are weighted heavily; and pages whose only function is to forward visitors elsewhere are treated as suspicious. External feeds matter as much as internal checks: browser vendors, anti-phishing consortia and direct abuse reports all route into the same queue. A confirmed match is removed and the address retired, and the host reports it onward so the URL is blocklisted rather than simply deleted. Legitimate content caught by the same signals goes to human review instead, where context from the uploader resolves it.

Real-World Example

An IT team publishes a staff awareness page on 99helpers showing annotated screenshots of a fake delivery-notice email and the sign-in screen it led to, with every field disabled and a header naming the exercise. The page is held automatically, since the screenshots contain a real brand and a login form. A short explanation in reply — internal training, no data collected, fields inert — clears the review. Had the form actually posted anywhere, it would have been removed instead, and rightly.

Common Mistakes

  • Building a pixel-perfect clone of a real sign-in page as a portfolio piece and publishing it unlabelled — it is indistinguishable from the real thing to a scanner
  • Leaving a live form on a training or demo page, which turns a mockup into something a host must treat as credential collection
  • Choosing a hostname containing a well-known brand name for an unofficial fan or demo page, which raises the impersonation score on its own
  • Ignoring a removal notice about a page you did not publish — a compromised account is a reason to answer quickly, not to wait

Related Terms

Put a file online in seconds

Drop in a document, an image, a page or a whole static website and share the link — free, with no build step and no server to set up.

Host a file free →