What is a fake Steam login page?
A fake Steam login page is a web page built to look exactly like Steam's sign-in screen. It has the Steam logo, the same fields, the same green button, often the same Steam Guard prompt. The only thing it does not have is Steam behind it. Whatever you type goes to the person who built the page.
These pages are the front door of most skin theft. API key scams, trade redirection, inventory wipes, all of them usually start with someone typing their password into a page that was not Steam. Valve's Account Security Recommendations call this phishing and give the one rule that matters: "If you suspect a site asking for your login information is not an official Steam site, do not enter any information on the site and disregard it."
This guide shows you how to tell, in a few seconds, and what to do if you already typed.
How do you tell a real Steam login from a fake one?
Read the address bar. That is it. Everything else on the page can be copied.
Valve lists the official login domains on its security page: "All official Steam logins are directed to the www.steampowered.com, store.steampowered.com, steamcommunity.com, or help.steampowered.com domains."
So the check is:
- Look at the address bar of the window that is asking for your password.
- Find the part right before the first single slash. That is the domain.
- It must end in exactly
steampowered.comorsteamcommunity.com. Notsteamcommunity.com.something.net. Notsteamcomunity.com. Notsteam-community.com. - If it does not, close the window. Do not type anything.
Here is what real and fake tend to look like side by side.
| What you see | Real Steam login | Fake Steam login |
|---|---|---|
| Domain | steamcommunity.com or steampowered.com, exactly | Anything else, including close lookalikes |
| Where it opens | A new browser window or tab with its own address bar | Often a "window" drawn inside the site's page, or a tab on the scam domain |
| Padlock | Yes | Usually also yes, so it proves nothing |
| Design | Steam's current design | Sometimes Steam's current design, sometimes last year's |
| What it asks for | Account name, password, then a Steam Guard code or app approval | The same, sometimes also your recovery code or "backup codes" |
| After login | You return to the site, already signed in | Often an error, a "try again", or a redirect to the real Steam |
That last row is a good tell after the fact. If you logged in and got an error, then logged in again and it worked, you may have typed your details into a fake page first and the real one second.
What do fake Steam login pages look like in 2026?
The pages keep getting better. Three patterns are common right now.
The drawn popup. The scam site draws a fake browser window inside its own page, complete with a fake address bar reading steamcommunity.com. It looks like a popup. It is an image with input boxes. The test: try to drag the popup outside the edge of your browser. A real popup window can leave the page. A drawn one is stuck inside it. You can also resize your browser; a real window does not shrink with the page behind it.
The lookalike domain. The page is a real, separate page, but on a domain one character off. Swapped letters, a missing letter, an extra word, or a different ending. Some use letters from other alphabets that look identical to Latin ones. Reading carefully catches most of these. The scam link checker catches the rest.
The redirect chain. You click "Sign in through Steam" and go through two or three quick redirects, ending on a page that looks like Steam. The redirects exist so that the link you were sent looks clean. The address bar at the end is what counts.
None of these can fake the real address bar of a real window. That is why the whole check comes down to that one line of text.
How does Sign in through Steam really work?
When a legitimate site offers "Sign in through Steam", it uses Steam's OpenID system. The site sends you to a page on steamcommunity.com. You log in there, on Steam's own domain. Steam then sends you back to the site with a confirmation that you are the owner of a particular Steam ID.
The site never sees your password. It never sees your Steam Guard code. It only learns your Steam ID and public profile. That is the design. A site cannot log in as you through this system.
This is why a fake login page has to exist at all. Since the real system gives sites nothing useful for theft, scammers have to imitate the login screen to get the password directly.
It also means a real site has no reason to show you a Steam login on its own domain. If the fields for your Steam password are on somesite.gg, they are fake by definition.
If you use the Steam Mobile app, there is a safer option. Valve's Mobile Authenticator FAQ describes QR code sign-in: scan the code on the login page with the app, and the app shows you a confirmation with "a map and the approximate geolocation of the device you're signing in to." No password is typed anywhere. A fake page can show a fake QR code, so the domain check still applies, but there is no password for the page to steal.
Where do fake login links come from?
Nobody stumbles onto a fake login page by typing the address. They arrive by a link, and the link usually comes with a story. Valve's Scam FAQ covers the pattern: pressure, urgency, authority, or a deal that is too good.
Common routes:
- A friend's account. "Vote for my team", "check out this tournament", "I found a site giving away a knife." Valve's security page says to check links sent by friends because "their account may be compromised."
- A Steam profile comment or group invite with a link to a "giveaway".
- A Discord message from someone claiming to be a marketplace, a tournament organiser, or Steam. Valve says anyone talking about your account through Discord or Steam Chat does not represent Steam.
- A trading site itself. Some scam marketplaces exist only to show you a fake login. Our guide on how to spot scam trading sites covers the rest of the site-level checks.
- Search results and ads for a real marketplace's name that lead to a clone.
The story is designed to make you skip the address bar. Free knife, five minutes left, your account is about to be banned. Valve's Scam FAQ puts it simply: "Anyone who is pressuring you, offering you something unreasonable, or threatening your account with a lock or ban is a scammer."
What happens after you type your details into a fake page?
Fast things. The scammer or their script now has your account name, password and a live Steam Guard code. The code is good for about 30 seconds, per Valve's authenticator FAQ, so the login happens immediately.
Once inside, the usual moves are:
- Create a Steam Web API key on your account so they can watch and redirect your trade offers later. See Steam API key scams.
- Change nothing visible, so you do not notice.
- Wait for you to send a trade offer, then swap it. Or trade your items to their account directly if your account does not need mobile confirmations.
- Sometimes, change your profile to look like it is under a ban threat, as part of a pressure scam. Valve's trade redirection page warns that Steam Support never edits your profile to threaten a ban.
If they got your email password too, they can also reset your Steam password at will.
The good news since July 2025: CS2 items traded away can be reversed within 7 days by the sender, per Valve's Trade Protected Items FAQ. The trade hold calculator shows when that window closes for a given trade. But the reversal is only useful if you notice, and it comes with a 30-day cooldown. Better to catch it at the login step.
What do you do if you already logged in to a fake page?
Treat your password and code as stolen and move quickly.
- Change your Steam password now, from a device you trust, through the Steam client or a page you typed into the address bar yourself.
- Sign out everywhere. Valve's security page says to check your authorized devices and use the "Sign out everywhere" option if anything looks odd.
- Check your account email and phone number. If the scammer changed either, recover the account through Steam Support before anything else.
- Revoke any API key at steamcommunity.com/dev/apikey.
- Change your email password if the same password was used anywhere, or if the fake page asked for it.
- Check Trade History for trades you did not make. Reverse if needed and if it is within 7 days.
- Scan for malware in case the page also got you to download something.
- Report the account that sent you the link, through its profile, following Valve's reporting guide. If a friend's account sent it, report it as hijacked so Valve can lock it until they recover it.
If you typed only your username and then stopped, you are probably fine, but change the password anyway. It costs nothing.
How do you make fake login pages useless?
You cannot stop the pages from existing. You can make them fail every time.
- Type Steam's address yourself when you need to log in for a site. Log in on steamcommunity.com in one tab first, then go to the marketplace. Its "Sign in through Steam" will then usually just confirm, without asking for a password. If it asks for one anyway, that is a signal.
- Use QR login from the Steam Mobile app where possible, and read the location on the confirmation.
- Use a password manager. It fills your Steam password only on the real Steam domain. On a fake domain it offers nothing, which is a loud warning.
- Never type a Steam Guard code into a website you reached by a link. Valve's authenticator FAQ says never to enter codes into a site not run by Valve.
- Slow down when there is a story. Prizes, deadlines and ban threats are the wrapper, not the point.
Do these and a fake login page becomes a blank form you never fill in. Combine them with the account setup in how to secure your Steam account and most skin theft has nowhere to start.
