Welcome to notphishing.link — a completely legitimate, fully trusted domain that harvests your login credentials would never do you any harm. Feel free to click on anything. What could possibly go wrong?
It literally says so in the domain name. If it were phishing, they'd call it phishing.link, right? The logic is airtight.
Purely for trust verification purposes. Your password goes straight to /dev/null, where it lives a happy life. This is just a test domain — we don't send or store anything, we promise (and promises on the internet are legally binding).
We have a green padlock 🔒 and a slick terminal in the background. No real scammer would go to this much trouble with CSS animations.
This is a placeholder on a test domain. The whole page is a joke about social engineering — and a reminder that a name like “safe” doesn't make a site safe. Always check where you're really entering your data.
By clicking “Sign in” you agree to terms that don't exist, and confirm that you are a sensible person who would never actually do this.
If this had been real phishing — you'd have just handed someone your password.
Relax: we didn't send or store anything. These fields exist only to prove one thing — a domain name means nothing. “notphishing”, “secure”, “bank-login” — anyone can name a site that way.
Rule for life: check the address bar, turn on MFA, and never type passwords where someone suddenly “invited” you. 🔒