Question

What is a URL actually made of?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Several distinct parts, each doing a specific job — and being able to read them is a genuinely useful security skill, because most phishing depends on people misreading the one part that matters.

Taking https://shop.example.co.uk:443/products/hats?colour=red&size=2#reviews apart:

Scheme — https: — the protocol to use.

Host — shop.example.co.uk — which machine to contact. Read right to left: the top-level domain is uk, co.uk is the registrable suffix, and example is the registered domain — the part that identifies who owns it. Everything to the left is a subdomain chosen freely by that owner.

Port — :443 — usually omitted because each scheme has a default.

Path — /products/hats — which resource on that host.

Query string — ?colour=red&size=2 — parameters, in key-value pairs separated by ampersands.

Fragment — #reviews — a location within the page. The fragment is never sent to the server; it is handled entirely by the browser, which is why it does not appear in server logs.

The security point, stated plainly. The domain is the last two or three labels before the first single slash. So:

https://yourbank.com.evil.net/login is controlled by evil.net. The bank's name is merely a subdomain someone else created.

https://evil.net/yourbank.com/login is likewise evil.net; everything after the slash is the attacker's own path.

A padlock proves encryption, not honesty — anyone can obtain a certificate for a domain they control.

Other things worth recognising: percent-encoding, where %20 is a space, used to carry characters that are not URL-safe; the @ character, which historically allowed everything before it to be ignored, a classic deception; internationalised domains, where characters from other scripts can closely resemble Latin letters — the homograph attack, which browsers now mitigate by displaying such domains in an encoded form; and long tracking parameters, which are usually safe to delete.

Related Questions