The signed list and the tile captcha.
Anubis defends the login against automation and gives you a way to catch a clone.
The login shows six tiles, each a tilted character, next to a decoy input field whose name rotates on every page load. A bot fills the wrong field and trips the trap. You read the tiles and type into the visible real field. This frustrates automated phishing kits that cannot solve the tiles or track the rotating field names.
Anubis signs its mirror list with a PGP key you can verify. Verifying the signature proves an address came from the market and nobody edited it. The addresses on this page are checked against that signed list, and there is usually more than one onion live at once so a flood on one does not lock you out.
Everything a browser renders is handed to anybody who requests it, so copying a storefront is mechanical. Clones usually look better than the original, because whoever built one wants visitors comfortable enough not to pause. A polished page is evidence of nothing and a broken layout is usually a thin circuit rather than a fake.
Generating an address whose first characters match a target costs an attacker hours. Each additional character multiplies that work by thirty two, so matching a tail is out of reach. Checking the last eight characters first inverts the attacker economics: the part they could not afford to fake is the part you check, and the part they spent hours on is the part you check last.
Where the operator publishes address changes signed with a key you already hold, checking that signature beats every other method, because verifying it does not require trusting the directory you read the address on. Import the public key once and every announcement afterwards takes seconds.
A padlock or its absence, since onion addresses carry their own authentication and certificate warnings say nothing here. Search ranking, which describes optimisation rather than authenticity. A working login form, which works precisely because it is capturing what you type.
Close the tab. Do not sign in to see what happens and do not send a test amount. Then change any password reused elsewhere, because that reuse is where the damage from a captured credential actually lands.