Recommended Free Tools
Protect your accounts by using a unique password for each service, turning on the strongest multifactor authentication (MFA) that service supports, and verifying unexpected requests through a channel you trust independently. AI can make a scam email, text, image, or voice sound convincing; you do not need to identify whether it was AI-generated to stay safer. The key is not to follow a message’s login link, disclose a password or one-time code, or approve a login you did not start.
Why AI phishing is harder to judge by appearance
AI-generated writing, images, and voice can make an impersonation more plausible. The FBI warns that publicly shared audio, video, and photos can be used to create deepfakes or other AI-generated content in its Stay Safe Online: Simple Tips for Adults guidance. A familiar voice, polished wording, caller ID, logo, or personal detail is not proof that a request is genuine.
The practical risk is the action the request tries to make you take: entering credentials on a fake website, disclosing a one-time MFA code, or approving a login. The FBI describes criminals posing as financial-institution or support staff to obtain credentials and one-time codes in its online scams and safety guidance. Style alone is not a reliable way to tell whether a message is legitimate or AI-generated.
Secure accounts that can unlock others first
Start with accounts that control money, identity, or password recovery. In particular, secure your primary email account, mobile-carrier account, banking and payment accounts, and major social or identity accounts. A compromised email account may expose password-reset messages for other services, so protect its recovery email just as carefully.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
In each account’s official security settings, check which recovery email addresses and phone numbers are attached. Remove contact methods you no longer control. The precise setting names and recovery steps vary by provider; use that provider’s official help pages rather than relying on instructions in an unexpected message.
Use a different strong password for every account
A unique passphrase for each service limits the damage if one site exposes a password: the same credential cannot simply be tried on your other accounts. The FBI advises adults to use unique, strong passphrases and a reputable password manager in its online safety advice. A password manager can generate and retain distinct passwords so you do not have to memorize them all.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
If you discover that you reused a password on an account that may have been exposed, change it on every service where you used it. Do not send a password to someone who contacts you, even if they claim to be helping you secure an account.
Choose the strongest MFA method the service offers
MFA adds another check beyond a password, but the methods are not equally resistant to phishing. For consumers, the useful rule is to select the strongest option available in that account’s official security settings, then set up recovery in case you lose the device or key. Not every service offers every method.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Method | What to know |
|---|---|
| Supported passkey or FIDO2 security key | Prefer this when the service supports it. FIDO authentication is designed to resist fake-site credential capture. Confirm the account and your devices support the method, and set up the provider’s recovery options. The FBI recommends FIDO2-compliant security keys or device-bound passkeys for authentication and critical systems; CISA identifies security keys as a strong phishing-resistant MFA choice. |
| Authenticator app with number matching or domain display | A reasonable fallback when a phishing-resistant option is unavailable. Check that the displayed domain matches the service you intended to sign in to, and match the number shown on your login screen. FBI organizational guidance recommends number matching and domain display and warns against push-only approvals. |
| Rotating authenticator code | Better than having no MFA, but a scammer may still trick you into entering the code on a fake login page or disclosing it during an impersonation. |
| SMS or email code | Use when stronger methods are unavailable. These codes offer weaker protection and may be exposed to attacks such as SIM swaps or phishing. Never read a code to an unsolicited caller. |
| Push approval without context | Do not approve a login prompt you did not initiate. Repeated unexpected prompts may be an attempt to wear you down into approving access. |
CISA’s MFA guidance compares methods for small and medium businesses; its ordering is useful context, not a guarantee that every consumer service offers those options. CISA also cautions that some MFA forms remain vulnerable to phishing and related attacks. The FBI notes that some websites and apps offer passkeys, which it describes as safer than passwords in its consumer advice.
Verify unexpected emails, texts, and calls outside the message
For a surprise password-reset notice, fraud alert, delivery message, shared document, support call, or request to “secure” an account, do not use the supplied sign-in link or contact details. Open the provider’s known app, type a familiar web address, use a saved bookmark, or call a number from the organization’s official website or your payment card. Then check for the alert or request inside the account.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The FBI advises using bookmarks or favorites for login sites, avoiding links in unexpected messages, distrusting unsolicited callers, and never giving an employee a username, password, or one-time password (OTP) in its online scams and safety guidance. If the request is real, you can act through the official service without trusting the message that brought it to your attention.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to do if you receive an unexpected MFA prompt
- Deny the prompt. If you were not trying to sign in, do not approve it. Never share a displayed code with a caller or message sender.
- Go to the service independently. Open its known app or type its familiar address; do not follow a link in the prompt or a related message.
- Change the password if needed. If you suspect someone already has it, change it through the official site or app to a new, unique password.
- Review account access. Use the provider’s security settings to inspect active sessions and connected devices, and remove access you do not recognize.
- Check recovery methods. Confirm that the email addresses and phone numbers used to recover the account are still yours.
Repeated prompts can be an attempt to pressure you into approval. FBI guidance for organizations recommends number matching and domain display for authenticator apps and warns against push-only approvals; those features can help, but their availability depends on the service.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Act quickly if you gave away a password or code
- Contact the provider through a verified channel. Use the official app, a familiar website address, or a phone number published on the provider’s official site or your payment card. Follow its account-recovery process.
- Change exposed credentials. Set a new, unique password for the affected account and for any other account where you reused that password.
- Secure recovery and sign-in access. Review recovery email addresses and phone numbers, active sessions, and connected devices in the account’s security settings.
- Check financial activity. If a financial account may be involved, contact the institution promptly and review transactions for unauthorized withdrawals, transfers, or purchases. The FBI recommends contacting a financial institution as soon as fraud is recognized and monitoring for unauthorized activity in its online scams and safety guidance.
- Report losses or suspected crime. Use the applicable official reporting channel in your jurisdiction. The FBI directs victims to the Internet Crime Complaint Center (IC3) in its adult online safety guidance.
Provider recovery procedures and reporting options differ, so follow the official instructions for the affected account and your location.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

