Enable passkeys or FIDO/WebAuthn security keys wherever your important accounts support them, starting with your primary email and accounts that can reset or unlock other accounts. Then review recovery options and fallback sign-in methods: a phishing-resistant passkey cannot protect an account if a weaker recovery route is still easy to exploit.
Why passkeys help against phishing
A passkey is a cryptographic credential associated with a particular website or app. The service stores a public key; the private key remains with your device, security key, or passkey provider. A device PIN or biometric authorizes use locally—your face or fingerprint is not sent to the website as the passkey.
Because a passkey is bound to the legitimate service, a lookalike phishing site cannot simply collect a reusable passkey secret. The Cybersecurity and Infrastructure Security Agency (CISA) calls FIDO/WebAuthn the only widely available phishing-resistant authentication: CISA’s More than a Password guidance. Passkeys do not, however, eliminate account recovery risks, protect every active session, or guarantee that every service has implemented its flows safely.
Choose an authentication method that fits the account
| Method | Phishing resistance | Portability and recovery | Practical use |
|---|---|---|---|
| Synced passkey | Phishing-resistant when correctly implemented | Can sync across supported devices; recovery depends on the provider account and its protections | A convenient choice for many personal accounts. Protect the provider account and understand how its recovery works. |
| Device-bound passkey on a security key | Phishing-resistant | Tied to the physical key; a spare key or service recovery route matters | Useful as a separate physical credential or for signing in across devices. Confirm FIDO/WebAuthn support at each service. |
| Authenticator-app code or number-matching push | Not phishing-resistant, according to CISA | Depends on the app’s and device’s recovery options | Use when FIDO is unavailable; never approve an unexpected prompt. |
| SMS code | Not phishing-resistant; can be exposed to phishing, SIM swapping, or telecom interception | Depends on access to the phone number and the service’s recovery rules | Use only when stronger options are unavailable, and remove it as a fallback when you have verified a safer alternative. |
Synced passkeys trade some separation from the provider for easier access across devices. Device-bound credentials stay with their authenticator. Both can offer phishing-resistant sign-in when correctly implemented. NIST’s April 23, 2024 announcement says correctly implemented syncable authenticators provide phishing resistance alongside simplified recovery and cross-device support: NIST’s supplement announcement.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Secure accounts in order of their impact
- Start with primary email. It may receive password resets and security alerts for many other services.
- Secure identity-provider accounts. Prioritize accounts such as Google, Apple, or Microsoft if you use them to sign in elsewhere or manage your devices and passkeys.
- Protect financial accounts. Use a passkey or security key if supported, and check the account’s recovery and verification settings.
- Continue with cloud storage, social profiles, and work access. Include any account that contains important data, reaches other people, or grants access to organizational resources.
CISA advises identifying valuable accounts and using FIDO-based authentication for key accounts where feasible. A practical inventory can be a simple list of services, their sign-in method, and the recovery route you would use if your usual device were lost.
Set up a passkey or security key
- Open the service’s security settings. Look for labels such as “Passkeys,” “Security keys,” “FIDO,” “WebAuthn,” “MFA,” or “two-step verification.” The names and available options vary by provider.
- Choose a personal device or compatible FIDO2 security key. Do not create a passkey on a shared device. Follow the service’s verification flow and confirm the new credential appears in its security settings.
- Add another way back in. When practical, enroll a second passkey or spare security key. If using synced passkeys, learn how the provider restores access and secure that provider account.
- Review fallback methods before changing them. Check recovery email, phone number, backup codes, active sessions, and alternative MFA. Disable SMS or another weaker fallback only after confirming that a safer recovery method works and you will retain access to it.
For example, Google documents passkey support across recent Windows, macOS, ChromeOS, Android, and iOS devices, but its minimum versions and supported browsers can change. Check the service’s current requirements rather than assuming a particular device or browser will work: Google Account Help on passkeys.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Plan for a lost device or security key
A device-bound passkey may be unavailable if its device is lost or damaged. A synced passkey may be easier to restore, but restoration depends on the passkey provider’s account protections and recovery process. FIDO recommends keeping alternative authentication or recovery options even when credentials sync: FIDO Alliance’s passkey overview.
- Enroll a second passkey or backup key when the service permits it; store a physical spare somewhere separate and secure.
- Keep recovery contact details current and store backup codes somewhere you can reach if your usual device is unavailable.
- Before removing an old phone, key, or recovery method, confirm that another sign-in route works.
- Review the provider’s current recovery instructions. Recovery requirements differ across services; Apple’s iCloud Keychain process, for example, may involve an Apple Account password, a registered phone number, and a device passcode, but that flow is not universal: Apple Support’s passkey and iCloud Keychain information.
Check what a passkey changes—and what it does not
Adding a passkey does not necessarily remove your existing authentication or recovery factors. On Google Accounts, a passkey can serve in place of the second step for 2-Step Verification, while existing factors and recovery options remain unless you change them. Inspect the account’s settings instead of assuming enrollment has turned off SMS or other fallbacks: Google Account Help on passkeys.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
For accounts that do not offer FIDO/WebAuthn, turn on the strongest MFA available. CISA treats number-matching push and authenticator codes as useful interim choices compared with plain SMS, while warning that they are still not phishing-resistant. Reject unexpected approval requests, and use SMS only if stronger choices are unavailable. See CISA’s MFA guidance and CISA’s mobile communications guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When a hardware security key makes sense
A FIDO2 security key is optional, not a prerequisite. It can provide a separate phishing-resistant credential and serve as a spare, but its value depends on whether your services support it and whether you have a recovery plan. Confirm compatibility and enroll a backup or recovery route before relying on a key. FIDO describes security keys as one way to hold device-bound passkeys and as a possible recovery credential: FIDO Alliance’s passkey overview.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
FIDO Alliance reports that passkey sign-ins are “up to 75% faster” and “20% more successful” than passwords or passwords plus a second factor such as SMS OTP. Those are figures reported on its consumer use-case page, whose excerpt does not identify underlying study details; they should not be treated as guaranteed outcomes for every user or service: FIDO Alliance’s Consumer Passkey Use Cases.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

