Phishing-resistant MFA: what qualifies and what does not
Phishing-resistant MFA stops fake login pages from stealing your second factor. Which methods qualify (passkeys, security keys) and which do not (SMS, codes).
Login securityPublished
Phishing-resistant MFA is multi-factor authentication where a fake website cannot collect anything that works on the real one. You do not need to spot the fake: the technology does it for you. This is different from most second factors in use today, where a clever fake page can ask for your password and your code and use both at once.
The US standards body NIST describes phishing resistance as the ability of an authentication protocol to detect and prevent disclosure of secrets and valid authenticator outputs to an impostor website without relying on the user’s vigilance (NIST SP 800-63B-4). That definition is useful far beyond the United States, because it makes clear what matters: the method, not the user’s attention.
Why ordinary MFA can still be phished
A common attack tool is a proxy page. You get a message pointing to a fake login page that looks exactly like the real one. You type your username, password and then the code from your SMS or authenticator app. The fake page passes all of it straight to the real site and logs in as you, and then it captures the session. You noticed nothing, the code was valid, and the attacker is in.
Attacks of this kind are called adversary-in-the-middle phishing. They are widely available as kits and can be used even by low-skilled criminals. That does not make every email dangerous, but it shows why a stronger method is worth having for key accounts.
What qualifies as phishing-resistant
Passkeys
A passkey is bound to the genuine domain. If you land on a fake site, the browser does not find a matching passkey and so offers nothing. Passkeys that sync across your devices and device-bound ones both work this way. See passkeys explained.
FIDO2 hardware security keys
A physical key also checks the domain before it signs. It is the same mechanism as a passkey, with the secret kept in a separate device. See hardware security keys and our overview of FIDO2 and WebAuthn.
Certificate-based methods
Smart cards and certificate-based authentication, such as those used in some company and government environments, use mutual cryptographic checks and also resist phishing. In Europe, national electronic ID cards with a chip can serve in the same role for some online services, depending on the country and service.
What does not qualify
| Method | Why it can be phished |
|---|---|
| Password alone | Typed into a fake page |
| SMS or email code | Typed into a fake page, or redirected |
| Authenticator-app code (TOTP) | Typed into a fake page and relayed in real time |
| Push approval | Can be approved on the false belief that it is your own login |
| Push with number matching | Reduces accidental approval, but the proof is still not tied to the site |
| Security questions | Known or guessable, and typed into the fake page |
None of these are useless. They stop credential stuffing and many ordinary attacks, so they are worth using. They are simply not at the level of the methods above.
The weak spot: recovery
An attacker who cannot beat your passkey will look for the easiest alternative route. If you can reset the account with an SMS code or an email link, that route is as strong as the weakest one allows. When you adopt phishing-resistant MFA:
- Remove weaker methods as login options where the service lets you.
- Tighten the recovery options and keep them minimal and safe.
- Keep a hardware key or passkey on a second device as backup.
- Store backup codes offline.
Our account recovery guide goes through these steps.
Who is pushing for it
Standards bodies and regulators increasingly point to phishing-resistant methods. NIST’s current guidance requires phishing-resistant authentication at its highest assurance level and treats SMS as a restricted method. In the EU, the NIS2 directive asks essential and important entities to use multi-factor or continuous authentication as part of their risk management. For private users the BSI describes passkeys as largely immune to the usual phishing attacks.
Habits that still help
Phishing-resistant methods take the pressure off, but good habits cost nothing and cover the accounts that cannot yet use them:
- Open important sites through a bookmark or the official app rather than a link in a message.
- Be wary of urgency, such as “your account will be closed within an hour”.
- Check that the address in the browser matches the service before entering anything.
- If you have entered a password or code on a page you doubt, change the password at once from the official site and look at your account’s recent activity.
A staged plan
- Today: switch on any two-factor authentication that is missing, starting with email.
- This month: create passkeys for your email, Apple, Google or Microsoft account and your password manager.
- When it suits: buy two hardware keys for the accounts you cannot afford to lose, see best hardware security keys.
- Over time: replace SMS and app codes with passkeys wherever services offer them.
You do not need to rebuild everything at once. Each step removes a layer of risk, and the most important step is the first one.
Frequently asked questions
What is phishing-resistant MFA in one sentence?
It is multi-factor authentication where the login proof is bound to the real website, so a fake site cannot capture something it can reuse to get into your account.
Is an authenticator app phishing-resistant?
No. A code from an authenticator app is better than SMS, but if you type it into a convincing fake site, the attacker can use it on the real site within seconds. It is still a good choice where nothing stronger exists.
Are push notifications with number matching phishing-resistant?
Number matching reduces accidental approvals and prompt-bombing, which helps. A real-time relay attack on a fake page can still trick you into approving, so push does not meet the definition of phishing-resistant.
Are synced passkeys phishing-resistant?
Yes, passkeys are bound to the website regardless of whether they sync. Synced passkeys depend on the security of the account that syncs them, so protect that account well.
Do I need phishing-resistant MFA as a private person?
It is the best protection available, and it is increasingly easy with passkeys. You do not need it everywhere at once. Start with the accounts whose takeover would hurt most.
More in Login security
Account recovery: how to plan it before you need it
Locked out of Google, Apple or your email? Set up recovery options, backup codes and a trusted contact now, and test them, so a lost phone is an annoyance.
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
How authenticator codes (TOTP) work and how to use them
TOTP codes are the six-digit numbers in authenticator apps. See how they are generated, why they work offline, their limits and how to back them up safely.