The fact that your password manager wouldn't offer to fill-in the password field of the fake login page (due to the domain being unknown) should make you raise an eyebrow.
I say "hygiene" because--like handwashing after the toilet--it's something everyone can do without particular tools or expertise.
Archetypal Aunt Tillie's "password manager" will be a handwritten piece of paper, but the rule of "only log-in with this bookmark and assume other prompts are lies" will still work.
This. Depending on your policy or org’s policy, your auth session may be short lived. Going to Google to login and come back every hour is a worse experience. Use your password manager. It will bind the credentials to the domains.
Archetypal Aunt Tillie's "password manager" will be a handwritten piece of paper, but the rule of "only log-in with this bookmark and assume other prompts are lies" will still work.