The signed list and the captcha check.
Nexus builds its access flow around phishing defence, and two checks confirm you are on a genuine address.
The Nexus login renders the market's own onion address into the captcha image. Compare that printed address against the one in your browser bar. A clone can copy the Nexus theme in minutes, but it cannot easily serve the correct address in the captcha while sending you to the wrong one, so a mismatch gives it away. Run this every session.
Nexus signs its mirror list with a PGP key you can verify. Verifying the signature proves an address came from the market and nobody edited it. The addresses on this page are checked against that signed list.
The design of a marketplace is served to anybody who loads it, so copying the look takes minutes and costs nothing. What a copy cannot do is live at the real onion address, because that address is derived mathematically from a key it does not hold. Printing the real address inside the login means a clone has to either display the wrong address or break its own login. That contradiction is the whole test.
Compare from the end rather than the beginning. Anybody generating a lookalike spends their computing time on a convincing prefix, since the prefix is what people glance at, and leaves the rest random. The tail is expensive to match and is where a fake gives itself away. Checking only the first few characters is the same as not checking.
A signed announcement proves the address came from the holder of the market key and that nobody edited it in transit. It is stronger than any directory, including this one, because verifying it does not require trusting the publisher. Import the public key once and every announcement afterwards takes seconds to check.
The page looking correct. A working login form, which works because it is collecting what you type. A padlock or its absence, since onion addresses carry their own authentication and browser certificate warnings say nothing useful here. And a search ranking, which is a statement about popularity rather than authenticity.
Close the tab. Do not sign in to see what happens, do not send a test amount, and do not report it from that page. Then change any password you reused elsewhere, because reuse is where the real damage from a harvested credential comes from.