How people arrive at the clone
Paid advertisements above genuine search results. Replies and quote-posts under official announcements. Compromised community servers posting a "new domain". Direct messages from accounts that copied a real profile. QR codes in images.
Notice what these share: in every case the link came to you. Almost nobody reaches a phishing site by typing an address they already knew.
The lookalike domain tricks
Character substitution that is hard to see at a glance, extra hyphens, a different top-level domain, a subdomain arrangement that puts the real name where the path should be, and internationalised characters that render identically to Latin ones.
Reading a domain carefully once is far more reliable than trying to spot these under time pressure.
The habit that works
Reach the site from your own bookmark, created from an address you verified once. Never from a message, an advertisement or a search result. If you must search, verify the domain before connecting anything.
FBT Swap has exactly one official domain: fbtswap.ir. Any other address using the name is not us, including addresses that look like a regional or backup version.
If you already connected
Connecting alone grants nothing. Check whether you approved any transaction or signed any message; if you did, assume the permission is live. Move assets to a fresh wallet, then revoke allowances on the old address.
Do not use a "revoke" link provided by the same source. Navigate to the explorer or a revocation tool by typing the address yourself.