Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you are not sure a sign-in page is genuine, do not enter your password. Close it and reach the service independently through a bookmark, a web address you already know, or its genuine app. A familiar logo, HTTPS, or a polished design cannot prove that a login page belongs to the company it names.

Check how you reached the login page

Pause if the page appeared after an unexpected email, text, advertisement, or redirect. Be especially wary of messages claiming that your account is suspended, a payment failed, suspicious activity occurred, or you must confirm personal or payment information urgently. The Federal Trade Commission (FTC) warns that phishing messages often impersonate companies and use account or billing problems to prompt people to click. FTC: How To Recognize and Avoid Phishing Scams

Context is a clue, not a verdict: a message can look familiar and still be fraudulent. Do not use the message’s link or contact details to check whether its claim is real. Instead, visit the service through a route you trust or contact it using details you already know are genuine.

Inspect the actual web address

Read the address shown in your browser, not just the company name, logo, or text displayed on the page. Compare the domain with the service’s genuine sign-in address, if you know it. Watch for misspellings, unexpected extra words, or a confusing subdomain. A familiar-looking page can be copied, so its design is not proof of identity. The FTC advises people to verify a message through a phone number, email address, or website known to be real—not the information in the message. FTC phishing guidance

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

HTTPS and a padlock indicate an encrypted connection; they do not establish that the site is operated by the service you intended to visit. Do not treat either as a reason to enter your password.

Use a trusted route instead of testing a suspicious link

  1. Close the questionable page. Do not enter credentials or follow another link on it to confirm whether it is legitimate.
  2. Open the service independently. Use a saved bookmark, type an address you already know, or open the service’s genuine app.
  3. Check the account there. If the message said there is a billing issue, account hold, or suspicious sign-in, look for the alert after signing in through that trusted route.
  4. Contact the company if needed. Use a phone number or website you already know is real, not contact information supplied in the unexpected message. FTC guidance on verifying unexpected messages

Take browser warnings seriously, but do not rely on silence

If Chrome warns that a page may be phishing or that a password may have been compromised, stop and follow the warning. Google advises changing a password promptly if Chrome says it may have been compromised; if you reused it, change it on the other accounts too. Google Account Help: Change unsafe passwords in your Google Account

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Chrome Safe Browsing protection depends on the selected setting and the signals available. Google describes different protection and data-handling behavior for Standard and Enhanced protection. A warning is a reason to stop, but the absence of a warning is not proof that a page is genuine or that every browser checks every page in the same way. Google Chrome Help: Safe Browsing

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you already entered your password or other details

Password entered

Go to the genuine service independently and change the password as soon as possible. Change it anywhere else you reused it, and enable two-factor authentication if available. If you cannot sign in, use the service’s official account-recovery route. These are the FTC’s recommended steps after giving account credentials to a scammer. FTC: What To Do If You Were Scammed

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The FTC notes that multi-factor authentication makes it harder for scammers to access an account even if they obtain its username and password. A security key is one possible MFA credential, but whether it works depends on the account and device. FTC phishing guidance

Payment, bank, or identity details entered

Contact the relevant bank, card issuer, or other provider through a known official channel and follow its instructions. If you gave out sensitive personal information, the FTC directs people to IdentityTheft.gov for situation-specific recovery help. FTC: What To Do If You Were Scammed

Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Report phishing attempts

The following reporting routes are U.S.-oriented. The FTC says to forward phishing emails to reportphishing@apwg.org, forward phishing texts to SPAM (7726), and report scams at ReportFraud.ftc.gov. Google also accepts reports of phishing pages found on the web, including sponsored search results. Google Safe Browsing: Report phishing Readers elsewhere should use their national cybercrime or consumer-protection reporting service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.