How trust-filtering prevents phishing in search results
Phishing works because it arrives looking ordinary. A search for a bank login, a parcel tracking page or a government form returns a list of blue links, and a convincing fake sitting among them inherits the credibility of the list it appears in. Trust-filtering attacks that problem at its source: the fake never appears in the list.
Why search results are a phishing channel
Ranking systems reward relevance, freshness and links. None of those measure honesty. A page built purely to imitate a well-known sign-in screen is, on paper, highly relevant to someone searching for that sign-in screen — and a paid placement or a briefly promoted page can sit above the genuine result long enough to collect credentials before it is reported.
Blocklists help, but they are reactive by nature. A domain has to be reported, verified and distributed before it is blocked, and most phishing campaigns are designed to finish their work inside that window. Assessing the live site at the moment of the search closes it.
What happens between your search and the page
- Candidates are retrieved. Relevant pages are gathered from the open web, unfiltered, exactly as an ordinary search engine would gather them.
- Each destination is assessed. The website behind every candidate result is checked live by Sapher, in parallel, so the whole page is judged rather than a sample of it.
- Anything that fails is removed. Failing sites, and sites that could not be assessed at all, never reach the page — not as a link, not as a thumbnail, not as a citation in an AI answer.
The signals that expose an impersonation
No single signal decides anything. A score is assembled from many observations of the live site, then Sapher's own analysis is applied on top. These are the signals that matter most for phishing specifically.
- Look-alike and confusable spellings
- Phishing domains almost always borrow the shape of a real name: a swapped letter, an inserted hyphen, a doubled character, a different suffix, or characters from another alphabet that render like Latin ones. A person skim-reading an address bar will miss these; a character-by-character comparison against known brand patterns will not.
- Throwaway registration patterns
- Fraud campaigns need domains that are cheap, instant and disposable. Certain suffixes, freshly registered addresses and long keyword-stuffed hostnames appear far more often in phishing than in ordinary business use, so they subtract from the score rather than add to it.
- Certificates that do not match the promise
- A padlock only means the connection is encrypted, not that the site is honest. The assessment checks that the certificate genuinely matches the address being visited, and treats a mismatch, an expired certificate or a downgrade to plain HTTP as a serious problem.
- Redirects away from the address you clicked
- A common trick is to advertise a plausible address that immediately forwards visitors somewhere else. Because the destination decides what you actually see, the destination is what gets judged — a clean-looking front door does not launder an unsafe building.
- Missing identity and contact details
- Real businesses publish who they are: contact details, a privacy notice, terms, an address, an ABN or company number. Credential-harvesting pages typically publish none of this, because everything on the page exists only to capture a login or a card number.
- Phishing keywords in the address itself
- Words such as verify, secure-login, account-update and billing-confirm attached to an unrelated brand name are far more common on fake sign-in pages than on the genuine ones they imitate.
Removing a link beats warning about it
Interstitial warnings and red badges rely on the person reading them and then choosing the cautious option — usually while distracted, in a hurry, or already half-convinced by a message telling them their account is about to be suspended. Warnings that appear often enough to be useful are also ignored often enough to be useless.
Removal takes the decision away entirely. A link that is not on the page cannot be clicked by mistake, cannot be copied, and cannot be reached by a screen reader or a keyboard user who never saw the warning styling in the first place. The cost is a shorter results list; the benefit is that everything on it has been checked.
Filtering applies to the whole page, not just the links
A filter that only cleans the list of blue links leaves several open doors. Image and video thumbnails load only from sites that passed. Map and local business results appear only once their website has been assessed. Shop prices are read from product pages on shops that passed. AI answers are shown only the pages that passed, so an unsafe site cannot be quoted, summarised or cited into visibility.
What trust-filtering does not do
Being honest about the boundaries is part of being trustworthy.
- A site can be honest today and compromised next week. A score describes the moment it was taken, which is why scores expire and sites are reassessed.
- Links you follow after leaving Marisei have not been assessed. A trusted site can still link onwards to somewhere we have never seen.
- Phishing delivered by email, SMS or messaging apps never passes through a search engine at all. Trust-filtering protects the search path, not every path. To assess phishing links from emails, txt messages or messaging apps, download our free browser extension from saphershield.com
- No automated assessment is perfect. Some fraudulent sites are well-built enough to pass, and some legitimate sites are removed because they could not be assessed in time.
Keep reading
- Fail-closed vs fail-open security — what happens when a check cannot finish.
- How Marisei Search works — the three steps behind every search.
- Frequently asked questions — scoring, pass marks and reporting a missing site.
