Archive > Verification and authenticity > NM-004
Everything visible about a web page can be reproduced. The stylesheet, the images, the wording, the layout and the captcha design are all served to whoever requests the page, which means a copy can be visually identical to the original. Judging authenticity by appearance is therefore not a check.
Nexus prints its onion address inside the anti-phishing image on the login screen and again in the page header. The check is to compare that printed address against the address shown by your browser. They match, or they do not.
A clone has to be reachable at some address, and that address is what your browser displays. It can print the genuine address on the page to reassure you, but then the page contradicts the address bar. It can print its own address, in which case the mismatch is obvious. There is no arrangement in which a copy sits at its own address, displays the real one, and remains consistent with what your browser shows.
Every session, without exception. A check performed only on a first visit is not a control, because the situation it defends against is precisely the one where you arrive by an unfamiliar route. It costs a few seconds and it is the single highest value action in this archive.
No genuine login requests a recovery phrase as part of signing in. A page that does is collecting accounts, and no further verification is required before closing it.
nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onionnexusma2iegzo7atzwbrwxhcdopyri3vare2twibldnlc3txqjdeb5yd.onionnexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onionRequired check. Open in Tor Browser only. Before entering anything, compare the onion printed on the login screen against your browser address bar. A mismatch means the page is a copy and the tab should be closed. See NM-004.