To set up phishing-resistant multifactor authentication (MFA), open the account’s security or sign-in settings and enroll a passkey or FIDO-compatible security key. Add a second supported authenticator and configure the account’s recovery options before you lose access to your current sign-in method. Exact menus and recovery steps vary by service.
What makes passkeys and security keys phishing-resistant?
Passkeys and security keys can use FIDO and WebAuthn, which bind authentication to the legitimate service’s domain. NIST explains that WebAuthn provides verifier name binding: the authenticator uses the authenticated domain when selecting its secret. A convincing fake site therefore cannot simply collect a manually entered code and replay it as though it came from the real site. See NIST SP 800-63B, under “Verifier Name Binding”.
A passkey is managed by a supported phone, computer, or platform; some passkeys can sync across devices. A roaming security key is a separate physical token, commonly connected through USB or NFC. NIST identifies both built-in and separate FIDO authenticator forms in its small-business MFA guidance.
One-time passcodes, text-message codes, and other manually entered outputs are not equivalent: NIST says they are not phishing-resistant because they are not bound to the specific session. Use them only when a service does not offer a phishing-resistant option or as a supported fallback—not as a like-for-like substitute.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Choose a passkey or a hardware security key
| Decision point | Passkey or platform authenticator | Hardware security key |
|---|---|---|
| Where it lives | Managed by a supported device or platform; some passkeys are syncable. | A separate physical token carried by the user. |
| Typical use | Authenticate with the device’s PIN or biometric; syncable passkeys may support use across devices. | Connect or tap the key when prompted. |
| Recovery consideration | Recovery depends on the platform or sync provider. NIST notes correctly implemented syncable authenticators can simplify recovery and cross-device use. | Register a second key if the service allows it; losing the only key may require the service’s account-recovery process. |
| Compatibility | Depends on the account, device, platform, browser, and any workplace policy. | Depends on service support and the key’s connection options, such as USB or NFC. |
| Often a good fit when | You want convenient sign-in on supported personal devices. | You want a distinct, portable physical authenticator or your organization requires one. |
These are practical trade-offs, not a universal security ranking. Choose based on what the service supports, your devices, organizational policy, and the recovery options you can maintain. NIST’s April 23, 2024 interim guidance on syncable authenticators addresses their recovery and cross-device role; not every provider implements syncing in the same way.
Set up a passkey or security key
- Open the account’s security settings. Sign in from a trusted device, then look for settings named Security, Sign-in, or MFA. Search the page for “passkey,” “security key,” “FIDO,” or “WebAuthn.” CISA recommends checking security settings on commonly used accounts and enabling MFA; see its consumer guidance.
- Select an offered phishing-resistant method. Choose a passkey managed by a supported device or a separate FIDO-compatible security key, subject to workplace policy. If buying a key, confirm the service accepts FIDO-standard keys and that its USB connector or NFC capability matches your devices. Compatibility is service-specific.
- Follow the service’s enrollment prompts. The exact sequence differs by account. For example, Login.gov’s security-key instructions say to give the key a nickname, insert it, and follow the browser prompts; Login.gov says a code is not needed to use the key. That is Login.gov’s flow, not a universal procedure.
- Add a backup authenticator. If allowed, enroll a second key or another supported authenticator. Store a backup key somewhere safe and separate enough to remain available if the primary key or device is lost. Login.gov, for example, permits multiple security keys.
- Configure recovery while you still have access. Follow the account’s own recovery instructions and store any recovery codes securely. Do not treat recovery codes as phishing-resistant sign-in: NIST states that “Look-up secrets are not phishing-resistant” in SP 800-63B.
- Confirm the new and backup routes. Use the service’s supported sign-in flow to confirm the new authenticator works, and check that your backup or recovery route is available before removing an existing method. Do not remove your current method until you understand how to regain access.
Plan for device loss and account recovery
Recovery is a service-specific part of setup, not a property guaranteed by the authenticator itself. Before relying on a passkey or key as your only route, check how the account handles a lost device, lost key, replacement phone, or unavailable sync account. Enroll multiple authenticators where possible, and keep recovery material protected from anyone who could use it to take over the account.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If your service offers only codes or another non-phishing-resistant fallback, treat that as a weaker recovery or sign-in route rather than assuming it has the same protection as FIDO/WebAuthn. Keep the fallback secured and follow the service’s instructions for replacing a lost authenticator.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Which accounts should you secure first?
Prioritize accounts that can unlock or affect many others: your primary email, financial accounts, work sign-in, remote access, and administrator accounts. CISA recommends MFA broadly, while NIST and CISA emphasize phishing-resistant authentication for sensitive systems and privileged users. Enable the strongest supported option for each account, while respecting any organization’s authentication policy.
Recommended Free Tools
Quick Recap
Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

