>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…
> getsupport.apple.com.phish.xyz I notice that a lot of scam texts use domains that start with a TLD followed by a hyphen, like: https://wa.gov-phish.fit/dol https://seattle.gov-phish.cc/dmv (Real examples, with "phish" replacing a string of 3-4 random letters) In some ways, it's a more convincing fake URL, since even if you're used to reading the domain right-to-left, your brain wants to start from the hyphen since…
This is how the scam page in OPs article is formatted, and I think it could easily fool a technical person who's tired. Precisely for the reason you touched on that when you're used to working with reverse DNS notation your eye is drawn to the last period. But hyphen and period are both used as "separators" in different contexts, so you have to be vigilant enough to override the natural instinct to chunk based on any separator.