Skip to content

Fake Steam Login Pages: How to Tell Real From Fake

Short answer

A fake Steam login page is a copy of Steam's sign-in screen hosted by a scammer to collect your account name, password and Steam Guard code. You tell it from the real one by reading the address bar: real Steam logins only happen on steamcommunity.com, store.steampowered.com, help.steampowered.com or steampowered.com.

Published Last updated

An M9 Bayonet Lore split into red and cyan ghost copies under an orange scanning beam, with an AWP Dragon Lore and an M4A4 Howl behind it.

What is a fake Steam login page?

A fake Steam login page is a web page built to look exactly like Steam's sign-in screen. It has the Steam logo, the same fields, the same green button, often the same Steam Guard prompt. The only thing it does not have is Steam behind it. Whatever you type goes to the person who built the page.

These pages are the front door of most skin theft. API key scams, trade redirection, inventory wipes, all of them usually start with someone typing their password into a page that was not Steam. Valve's Account Security Recommendations call this phishing and give the one rule that matters: "If you suspect a site asking for your login information is not an official Steam site, do not enter any information on the site and disregard it."

This guide shows you how to tell, in a few seconds, and what to do if you already typed.

How do you tell a real Steam login from a fake one?

Read the address bar. That is it. Everything else on the page can be copied.

Valve lists the official login domains on its security page: "All official Steam logins are directed to the www.steampowered.com, store.steampowered.com, steamcommunity.com, or help.steampowered.com domains."

So the check is:

  1. Look at the address bar of the window that is asking for your password.
  2. Find the part right before the first single slash. That is the domain.
  3. It must end in exactly steampowered.com or steamcommunity.com. Not steamcommunity.com.something.net. Not steamcomunity.com. Not steam-community.com.
  4. If it does not, close the window. Do not type anything.

Here is what real and fake tend to look like side by side.

What you seeReal Steam loginFake Steam login
Domainsteamcommunity.com or steampowered.com, exactlyAnything else, including close lookalikes
Where it opensA new browser window or tab with its own address barOften a "window" drawn inside the site's page, or a tab on the scam domain
PadlockYesUsually also yes, so it proves nothing
DesignSteam's current designSometimes Steam's current design, sometimes last year's
What it asks forAccount name, password, then a Steam Guard code or app approvalThe same, sometimes also your recovery code or "backup codes"
After loginYou return to the site, already signed inOften an error, a "try again", or a redirect to the real Steam

That last row is a good tell after the fact. If you logged in and got an error, then logged in again and it worked, you may have typed your details into a fake page first and the real one second.

What do fake Steam login pages look like in 2026?

The pages keep getting better. Three patterns are common right now.

The drawn popup. The scam site draws a fake browser window inside its own page, complete with a fake address bar reading steamcommunity.com. It looks like a popup. It is an image with input boxes. The test: try to drag the popup outside the edge of your browser. A real popup window can leave the page. A drawn one is stuck inside it. You can also resize your browser; a real window does not shrink with the page behind it.

The lookalike domain. The page is a real, separate page, but on a domain one character off. Swapped letters, a missing letter, an extra word, or a different ending. Some use letters from other alphabets that look identical to Latin ones. Reading carefully catches most of these. The scam link checker catches the rest.

The redirect chain. You click "Sign in through Steam" and go through two or three quick redirects, ending on a page that looks like Steam. The redirects exist so that the link you were sent looks clean. The address bar at the end is what counts.

None of these can fake the real address bar of a real window. That is why the whole check comes down to that one line of text.

How does Sign in through Steam really work?

When a legitimate site offers "Sign in through Steam", it uses Steam's OpenID system. The site sends you to a page on steamcommunity.com. You log in there, on Steam's own domain. Steam then sends you back to the site with a confirmation that you are the owner of a particular Steam ID.

The site never sees your password. It never sees your Steam Guard code. It only learns your Steam ID and public profile. That is the design. A site cannot log in as you through this system.

This is why a fake login page has to exist at all. Since the real system gives sites nothing useful for theft, scammers have to imitate the login screen to get the password directly.

It also means a real site has no reason to show you a Steam login on its own domain. If the fields for your Steam password are on somesite.gg, they are fake by definition.

If you use the Steam Mobile app, there is a safer option. Valve's Mobile Authenticator FAQ describes QR code sign-in: scan the code on the login page with the app, and the app shows you a confirmation with "a map and the approximate geolocation of the device you're signing in to." No password is typed anywhere. A fake page can show a fake QR code, so the domain check still applies, but there is no password for the page to steal.

Nobody stumbles onto a fake login page by typing the address. They arrive by a link, and the link usually comes with a story. Valve's Scam FAQ covers the pattern: pressure, urgency, authority, or a deal that is too good.

Common routes:

  • A friend's account. "Vote for my team", "check out this tournament", "I found a site giving away a knife." Valve's security page says to check links sent by friends because "their account may be compromised."
  • A Steam profile comment or group invite with a link to a "giveaway".
  • A Discord message from someone claiming to be a marketplace, a tournament organiser, or Steam. Valve says anyone talking about your account through Discord or Steam Chat does not represent Steam.
  • A trading site itself. Some scam marketplaces exist only to show you a fake login. Our guide on how to spot scam trading sites covers the rest of the site-level checks.
  • Search results and ads for a real marketplace's name that lead to a clone.

The story is designed to make you skip the address bar. Free knife, five minutes left, your account is about to be banned. Valve's Scam FAQ puts it simply: "Anyone who is pressuring you, offering you something unreasonable, or threatening your account with a lock or ban is a scammer."

What happens after you type your details into a fake page?

Fast things. The scammer or their script now has your account name, password and a live Steam Guard code. The code is good for about 30 seconds, per Valve's authenticator FAQ, so the login happens immediately.

Once inside, the usual moves are:

  1. Create a Steam Web API key on your account so they can watch and redirect your trade offers later. See Steam API key scams.
  2. Change nothing visible, so you do not notice.
  3. Wait for you to send a trade offer, then swap it. Or trade your items to their account directly if your account does not need mobile confirmations.
  4. Sometimes, change your profile to look like it is under a ban threat, as part of a pressure scam. Valve's trade redirection page warns that Steam Support never edits your profile to threaten a ban.

If they got your email password too, they can also reset your Steam password at will.

The good news since July 2025: CS2 items traded away can be reversed within 7 days by the sender, per Valve's Trade Protected Items FAQ. The trade hold calculator shows when that window closes for a given trade. But the reversal is only useful if you notice, and it comes with a 30-day cooldown. Better to catch it at the login step.

What do you do if you already logged in to a fake page?

Treat your password and code as stolen and move quickly.

  1. Change your Steam password now, from a device you trust, through the Steam client or a page you typed into the address bar yourself.
  2. Sign out everywhere. Valve's security page says to check your authorized devices and use the "Sign out everywhere" option if anything looks odd.
  3. Check your account email and phone number. If the scammer changed either, recover the account through Steam Support before anything else.
  4. Revoke any API key at steamcommunity.com/dev/apikey.
  5. Change your email password if the same password was used anywhere, or if the fake page asked for it.
  6. Check Trade History for trades you did not make. Reverse if needed and if it is within 7 days.
  7. Scan for malware in case the page also got you to download something.
  8. Report the account that sent you the link, through its profile, following Valve's reporting guide. If a friend's account sent it, report it as hijacked so Valve can lock it until they recover it.

If you typed only your username and then stopped, you are probably fine, but change the password anyway. It costs nothing.

How do you make fake login pages useless?

You cannot stop the pages from existing. You can make them fail every time.

  • Type Steam's address yourself when you need to log in for a site. Log in on steamcommunity.com in one tab first, then go to the marketplace. Its "Sign in through Steam" will then usually just confirm, without asking for a password. If it asks for one anyway, that is a signal.
  • Use QR login from the Steam Mobile app where possible, and read the location on the confirmation.
  • Use a password manager. It fills your Steam password only on the real Steam domain. On a fake domain it offers nothing, which is a loud warning.
  • Never type a Steam Guard code into a website you reached by a link. Valve's authenticator FAQ says never to enter codes into a site not run by Valve.
  • Slow down when there is a story. Prizes, deadlines and ban threats are the wrapper, not the point.

Do these and a fake login page becomes a blank form you never fill in. Combine them with the account setup in how to secure your Steam account and most skin theft has nowhere to start.

Sources

Frequently asked questions

What are the real Steam login domains?

Valve's security page lists them: www.steampowered.com, store.steampowered.com, steamcommunity.com and help.steampowered.com. A login page on any other domain is fake.

Can a fake login page steal my Steam Guard code?

Yes. The page asks for the code just like Steam does, then the scammer uses it within its 30-second life to log in. The mobile authenticator only protects you if you never type the code into a fake page.

Does the padlock icon mean a login page is real?

No. The padlock means the connection is encrypted. Scammers get certificates for free. Only the domain name tells you who you are talking to.

Why does the fake page open inside the website instead of a new tab?

Some fake pages draw a picture of a popup window, address bar included, inside the scam site's own page. Try dragging the popup outside the browser window. A real window moves; a drawn one cannot leave the page.

Can I get hacked just by visiting a fake page?

Normally no. The page needs you to type your details. The exception is a page that gets you to download and run something, which Valve's security page warns is a common malware route.

Does Steam ever ask me to log in to claim a prize?

No. Valve's security page says to use extreme caution with any link claiming free Steam content, and its Scam FAQ says Steam staff never contact you through chat about your account.

What is QR code login and is it safer?

The Steam Mobile app can scan a QR code on the sign-in page instead of you typing a password. The app then shows the location of the device trying to log in. It removes the password from the equation, but you still need to check that the QR code is on a real Steam domain.