When phishing the best way to do it would be to have a subdomain like so.
facebook.com.login.45234523.1q34512345.22456DOMAIN.com/index.php?=5t43253452352345oj2pk34t23456
But that is just an example.
facebook.com.video.play.cgibin.profile.2342341e12ed414ed.1243.DOMAIN
facebook.com.cgi.bin.webscr.cmd.login.submit.dispatch.31356489436156789456312302648994151511541512105451212548544.DOMAIN HERE
The list goes on.
Hope this helped.
Ps not all hosts allow such long subdomains, all the paid ones ive used have, free no.
i suggest .tk or .co.cu for the free extention.