To reduce the risk of AI-generated phishing, turn on multifactor authentication (MFA) for important accounts, use a phishing-resistant passkey or security key where supported, and protect workplace email domains with SPF, DKIM, and DMARC. These controls matter because a polished message can still be fraudulent: spelling and grammar are no longer reliable primary warning signs.
Why convincing phishing needs layered defenses
Generative AI can help attackers produce more polished messages and scale their campaigns. Microsoft’s Digital Defense Report 2025 reports that AI-automated phishing emails in its study achieved a 54% click-through rate, compared with 12% for standard attempts, which the report describes as a 4.5× increase. This is a Microsoft-reported study result, not a universal click-through rate.
Rather than relying on a message looking suspicious, reduce what an attacker can do if someone clicks or gives up credentials. Authentication controls help limit account takeover; domain protections address some forms of spoofing; endpoint detection and a fast reporting process help with messages that get through.
Choose MFA that resists phishing
Enable MFA on primary email and other high-impact accounts. Email deserves priority because it can often be used to reset passwords for other services. For workplace accounts, prioritize administrators, people with access to sensitive data, and users exposed to remote access. CISA advises enabling MFA and recommends the strongest method a service supports; its business guidance says any MFA is better than none. See CISA’s MFA guidance.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
When choosing a method, distinguish between a second step that can be relayed to an impostor and one that verifies the actual service. NIST defines phishing resistance as preventing authentication secrets or valid outputs from being disclosed to an impostor verifier without depending on the user’s vigilance. Its SP 800-63B standard identifies WebAuthn, used by FIDO2 authenticators, as an example: the authenticator binds its response to the legitimate verifier’s domain.
| Method | Phishing resistance | Practical consideration |
|---|---|---|
| FIDO2/WebAuthn security key or supported passkey | Phishing-resistant through verifier-name binding, as described by NIST. | Use only where the account and device support it; check compatibility and set up recovery. |
| Authenticator-app one-time code entered manually | Not phishing-resistant under NIST’s definition; a user can be tricked into entering a code on an impostor site. | Useful fallback when stronger methods are unavailable. |
| No MFA | No second authentication factor to help block use of a stolen password. | Turn on an available MFA method rather than leaving the account password-only. |
For physical keys, check the connector and whether the account and device support NFC or other required options before buying. A passkey’s availability and recovery behavior also vary by service. Follow the provider’s current setup instructions rather than assuming one method works everywhere.
Rank #2
Settings to change on personal accounts
- Secure the accounts that can unlock others. Start with your main email, then financial accounts, cloud storage, social accounts, and services used to reset other passwords. Turn on MFA and select a passkey or security key when supported.
- Set up recovery before you need it. Save recovery codes somewhere secure and configure a second recovery method. Confirm that you can still access the account if your primary phone or key is lost.
- Use unique passwords. A password manager can help create and store distinct passwords. MFA is an additional layer, not a reason to reuse passwords across accounts.
- Review privacy settings. Make social profiles private where appropriate and limit publicly visible personal details that could help someone impersonate you or craft a credible request.
Settings and controls for organizations
Require stronger authentication for critical access
Require MFA for email, file sharing, remote access, privileged accounts, and users handling sensitive information. Plan a staged move toward phishing-resistant FIDO2/WebAuthn methods, and test account recovery before broad rollout. Keep MFA requirements aligned with the systems and access paths employees actually use.
Configure SPF, DKIM, and DMARC for owned domains
These email-domain controls help recipients assess whether messages claiming to come from your organization are authorized. Configure and monitor them for domains the organization owns. They are anti-spoofing protections, not a complete phishing filter: they do not prevent phishing sent from a compromised legitimate account or from a lookalike domain. CISA discusses AI-related cyber risks and defensive measures in its guidance on generative AI risks.
Prepare to detect and contain account compromise
- Deploy and tune endpoint detection and response so suspicious activity on managed devices can be investigated.
- Provide a clear, easy-to-find way to report suspicious messages, and make sure reports reach a team that can act.
- Include procedures to revoke active sessions, reset credentials, and investigate unexpected mailbox rules or newly registered authentication methods.
- Restrict or monitor external collaboration and remote-access tools where appropriate.
Verify sensitive requests out of band
Train staff to report suspicious messages and to confirm unusual payment, credential, or sensitive-data requests through a known, separate channel—for example, a previously verified phone number or an established internal contact method. Do not use the link or contact details in the request itself to verify it.
Microsoft’s 2025 report also describes inbox flooding used to obscure security notifications and set up fake IT-support calls or remote-access scams. A sudden wave of messages should therefore prompt people to check for account alerts and report the activity, rather than treating the apparent message overload as harmless.
Rank #4
What these controls do—and do not—cover
| Control | Helps address | Does not replace |
|---|---|---|
| Phishing-resistant MFA | Use of stolen credentials at an impostor verifier. | Endpoint monitoring, recovery planning, or protection against every kind of account compromise. |
| SPF, DKIM, and DMARC | Some spoofing that abuses an organization’s own email domain. | Protection from compromised legitimate accounts or lookalike domains. |
| Endpoint detection and response | Suspicious activity on endpoints that can be monitored and investigated. | Email authentication or user reporting and verification. |
| Reporting and independent verification | Faster review of suspicious messages and confirmation of high-impact requests. | Technical account and domain protections. |
These controls cover different parts of the attack path, so use them together. No single setting can make every convincing message safe.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

