Your reply is missing the point and the difficulty of the topic.
Yes, _you_ know "chase.com.swag.ru" is wrong but the harder computer science question is: "How does a web browser deterministically evaluate if "chase.com.swag.ru" is not the real Chase bank the web surfer intends to reach?"
In other words, the FireFox/Chrome browser doesn't have a function such as:
if (ask_7steps2much_if_domain_is_real_instead_of_fake("chase.com.swag.ru")) then ...
The generalized way that's been attempted is Certificate Authorities being hardcoded/whitelisted inside of browsers, etc. This helps for encryption to prevent MITM attacks but has many loopholes for identity verification. LetsEncrypt dv certs are more helpful for encryption. In contrast, something like EV certificates was trying to help with trusted identity.But it looks like EV certificates were not a UI signal used by most web surfers so Chrome/Firefox dropped the visual indicators: https://www.google.com/search?q=chrome+firefox+remove+ev+cer...