About this tool
Split a student-portal login link into its parts and see whether the registrable domain really belongs to your institution.
A fake student portal works by putting your university's name somewhere in a web address where it carries no authority — a subdomain, a path, or the text before an @ sign — while the registrable domain belongs to the attacker. This page splits a link into scheme, user info, subdomain, registrable domain, port, path, query and fragment, marks the one part that decides where the browser connects, and compares it with the domain you already know. It also lists what the harvesting page itself gets wrong, from a silent password manager to a browser-in-the-browser popup.
Open University Portal Phishing Anatomy on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
The registrable domain is marked explicitly, so the lesson survives after you close the page: read the host right to left.
The @ sign, punycode look-alikes, long subdomain chains, plain HTTP sign-in pages and redirect parameters are all called out by name.
The link is analysed as text in your browser. It is never opened, resolved or reported anywhere, so checking a live phishing link is safe.
No. The browser reads the host from right to left, so the owner here is login-portal.com and everything to its left is a label that owner invented. A domain you can trust ends with the institution's own registrable domain immediately before the first single slash.
No, and that is why fake portals avoid them. The .edu namespace is limited to US postsecondary institutions accredited by an agency recognised by the US Department of Education, with the registry operated by Educause, and .ac.uk names are issued by Jisc only to eligible UK institutions. A commercial .com claiming to be a campus portal has skipped that check entirely.
No. A certificate proves you are talking to the domain in the address bar and that the connection is encrypted; it says nothing about who owns that domain or whether they are honest. Free certificates are issued in seconds to any domain the requester controls, including phishing domains.
Change the password on the real portal immediately, from a bookmark or an address you type yourself, then sign out all active sessions and check that no forwarding rule has been added to your mailbox. Report it to your university IT service desk the same day so the page can be blocked and any access reviewed.