Phishing has gone lower success rates than it was a decade ago. We know what the reasons are. People have become more consious about what's going on. They are already aware about these types of attacks and have learned to protect themseleves from it.
Long story short, people have started checking if the page where they are about to enter their creds is hosted under a valid domain.
Now what's the deal. I'll need you to help me card a laptop, or card me a laptop. And I will share you my knowledge about this technique.
What's the technique?
I will teach you how could you host your phishing page under a legitimate domain. You want a paypal login phish page hosted right under https://paypal.com/login ? Make a deal with me and let's help each other.