openideurope.eu

Phishing-resistant MFA: what qualifies and what does not

Phishing-resistant MFA stops fake login pages from stealing your second factor. Which methods qualify (passkeys, security keys) and which do not (SMS, codes).

Login securityPublished

Phishing-resistant MFA is multi-factor authentication where a fake website cannot collect anything that works on the real one. You do not need to spot the fake: the technology does it for you. This is different from most second factors in use today, where a clever fake page can ask for your password and your code and use both at once.

The US standards body NIST describes phishing resistance as the ability of an authentication protocol to detect and prevent disclosure of secrets and valid authenticator outputs to an impostor website without relying on the user’s vigilance (NIST SP 800-63B-4). That definition is useful far beyond the United States, because it makes clear what matters: the method, not the user’s attention.

Why ordinary MFA can still be phished

A common attack tool is a proxy page. You get a message pointing to a fake login page that looks exactly like the real one. You type your username, password and then the code from your SMS or authenticator app. The fake page passes all of it straight to the real site and logs in as you, and then it captures the session. You noticed nothing, the code was valid, and the attacker is in.

Attacks of this kind are called adversary-in-the-middle phishing. They are widely available as kits and can be used even by low-skilled criminals. That does not make every email dangerous, but it shows why a stronger method is worth having for key accounts.

What qualifies as phishing-resistant

Passkeys

A passkey is bound to the genuine domain. If you land on a fake site, the browser does not find a matching passkey and so offers nothing. Passkeys that sync across your devices and device-bound ones both work this way. See passkeys explained.

FIDO2 hardware security keys

A physical key also checks the domain before it signs. It is the same mechanism as a passkey, with the secret kept in a separate device. See hardware security keys and our overview of FIDO2 and WebAuthn.

Certificate-based methods

Smart cards and certificate-based authentication, such as those used in some company and government environments, use mutual cryptographic checks and also resist phishing. In Europe, national electronic ID cards with a chip can serve in the same role for some online services, depending on the country and service.

What does not qualify

Method Why it can be phished
Password alone Typed into a fake page
SMS or email code Typed into a fake page, or redirected
Authenticator-app code (TOTP) Typed into a fake page and relayed in real time
Push approval Can be approved on the false belief that it is your own login
Push with number matching Reduces accidental approval, but the proof is still not tied to the site
Security questions Known or guessable, and typed into the fake page

None of these are useless. They stop credential stuffing and many ordinary attacks, so they are worth using. They are simply not at the level of the methods above.

The weak spot: recovery

An attacker who cannot beat your passkey will look for the easiest alternative route. If you can reset the account with an SMS code or an email link, that route is as strong as the weakest one allows. When you adopt phishing-resistant MFA:

  1. Remove weaker methods as login options where the service lets you.
  2. Tighten the recovery options and keep them minimal and safe.
  3. Keep a hardware key or passkey on a second device as backup.
  4. Store backup codes offline.

Our account recovery guide goes through these steps.

Who is pushing for it

Standards bodies and regulators increasingly point to phishing-resistant methods. NIST’s current guidance requires phishing-resistant authentication at its highest assurance level and treats SMS as a restricted method. In the EU, the NIS2 directive asks essential and important entities to use multi-factor or continuous authentication as part of their risk management. For private users the BSI describes passkeys as largely immune to the usual phishing attacks.

Habits that still help

Phishing-resistant methods take the pressure off, but good habits cost nothing and cover the accounts that cannot yet use them:

  • Open important sites through a bookmark or the official app rather than a link in a message.
  • Be wary of urgency, such as “your account will be closed within an hour”.
  • Check that the address in the browser matches the service before entering anything.
  • If you have entered a password or code on a page you doubt, change the password at once from the official site and look at your account’s recent activity.

A staged plan

  1. Today: switch on any two-factor authentication that is missing, starting with email.
  2. This month: create passkeys for your email, Apple, Google or Microsoft account and your password manager.
  3. When it suits: buy two hardware keys for the accounts you cannot afford to lose, see best hardware security keys.
  4. Over time: replace SMS and app codes with passkeys wherever services offer them.

You do not need to rebuild everything at once. Each step removes a layer of risk, and the most important step is the first one.

Frequently asked questions

What is phishing-resistant MFA in one sentence?

It is multi-factor authentication where the login proof is bound to the real website, so a fake site cannot capture something it can reuse to get into your account.

Is an authenticator app phishing-resistant?

No. A code from an authenticator app is better than SMS, but if you type it into a convincing fake site, the attacker can use it on the real site within seconds. It is still a good choice where nothing stronger exists.

Are push notifications with number matching phishing-resistant?

Number matching reduces accidental approvals and prompt-bombing, which helps. A real-time relay attack on a fake page can still trick you into approving, so push does not meet the definition of phishing-resistant.

Are synced passkeys phishing-resistant?

Yes, passkeys are bound to the website regardless of whether they sync. Synced passkeys depend on the security of the account that syncs them, so protect that account well.

Do I need phishing-resistant MFA as a private person?

It is the best protection available, and it is increasingly easy with passkeys. You do not need it everywhere at once. Start with the accounts whose takeover would hurt most.

More in Login security