The domain always consists of the last two terms before the first standalone "/" in a web address (for example, in 'https://www.hs-anhalt.de/informationssicherheit/sicherheitstipps.html', it is hs-anhalt.de). The domain is the most important part for recognizing phishing URLs. When checking the domain, you should pay attention to the following points:
Domain with IP address
Is the area between "http://" and the third slash "/" an IP address, such as
https://95.130.22.98/hs-anhalt.de.secure-login.de/
then in this case, the IP address is the domain. This is in most cases an indicator of internet fraud. Do not follow this link!
Address outside the domain
If the address of the expected partner (e.g., hs-anhalt.de) is outside the domain, it is a fraudulent link.
It can look like this:
'http://www.hs-anhalt.de.letmein.com/ (here the domain is letmein.com)
http://letmein.com/https://www.hs-anhalt.de/ (here too, the domain is letmein.com)
Do not follow this link!
Domain with typos
Check the domain for typos, for example:
'http://www.hs-ahnalt.de
instead of
'http://www.hs-anhalt.de
Do not follow a link with typos!
Domain with similar characters
Check the domain for similar-looking characters and numbers (e.g., 'rn' instead of 'm' or '1' instead of 'l' or 'q' instead of 'p').
Example: 'https://www.hs-anhaIt.de/ (here the "l" is a capital "I") instead of 'https://www.hs-anhalt.de/
Do not follow this link!
Modifications of the domain
If the domain contains only a slight modification of the previously familiar domain, do not enter any data!
Example: 'https://www.pw.hs-anhalt.de/
These modifications are difficult to recognize because you need to know the correct domain.
If you are unsure whether you are on an "authentic" university website, please contact the ISC support.