Here are some tips from an Internet service provider, eBay, and Citibank on ways to avoid being phished.
Citibank warns its customers to check the security certificate for any site to which they're linked.
If the name doesn't match the company owning the site, you shouldn't trust the link. It also recognizes that not all certificates are held in a name recognized by consumers accessing the site, but the bank informs its customers that all security certificates for Citibank's sites are held in its "Citibank" name.
Since not all security certificate issuers police similar-sounding "brand-related" names when issuing their certificates, knowing the exact name of the security-certificate holder is key to authenticating the page. All sites should disclose the correct security-certificate holder name at their sites.
EBay teaches its members how to spot a fake eBay URL by checking the browser Web-address window. (Although, given the Microsoft Internet Explorer vulnerability that permits the URL appearance in the browser window to be spoofed, this tip may be ineffective for IE users.)