This is where you would have them insert credentials and/or serve your payload still using the legitimate domain.
CLICK HERE TO VIEW FILE