Is it possible to find out where a phishing website is sending there log ins?

I know that it is possible to have a phishing file and sniff it using bintext and be able to find out the email its sending its log ins to but could you do that to a phishing website to find out the email or web page its sending the log ins?

