How to Protect Yourself From Phishing Attacks
Phishing does not fool the careless. It fools careful people on a busy day. Here is how it actually works, and the small habits and tools that shut it down.
A message arrives that looks exactly right. Your bank, your email provider, a delivery company. It says there is a problem, it feels urgent, and it gives you a link to fix it. You click, you see a familiar login page, you type your password. Except the page was not your bank. That is phishing, and it is behind a huge share of account compromises.
The uncomfortable truth is that phishing does not rely on you being foolish. It relies on you being busy, trusting, and human. The defenses that work are not about being smarter than the scam every single time. They are about setting things up so that even a convincing fake cannot get what it wants.
Key takeaways
- Phishing works by imitating a site you trust and creating urgency so you act without checking.
- Never enter credentials on a page you reached by clicking a link; go to the site directly.
- A password manager ties each login to the real domain, so it will not autofill on a lookalike.
- Passkeys are phishing-resistant by design, because they only work on the genuine site.
How phishing actually works
A phishing attack has two parts: a lure and a trap. The lure is a message that looks like it comes from someone you trust and manufactures a reason to act quickly. Your account will be closed. A payment failed. Someone signed in from a new device. Urgency is the point, because a rushed brain skips the checks it would normally make.
The trap is a fake website that mimics the real one closely, right down to the logo and layout. When you type your password there, you are handing it straight to the attacker, who then uses it on the real site. Some traps even relay a 2FA code you enter, in real time. The whole scheme depends on one thing: convincing you to type a secret into the wrong place.
The habits that stop most phishing
You do not need to be a security expert. A few reliable habits catch the vast majority of attempts:
- Check the domain, not the design. Anyone can copy a logo. What they cannot easily copy is the exact web address. Look closely for extra words, hyphens, or swapped letters, like a "-secure" tacked on or a subtle misspelling.
- Never log in from a link. If a message says there is a problem with an account, do not use its link. Open the app or type the address yourself. The problem, if real, will be waiting for you there.
- Distrust urgency. Real institutions rarely demand that you act in the next five minutes or lose access. Pressure is a red flag, not a deadline.
- Remember that a padlock is not a promise. The padlock icon means the connection is encrypted, not that the site is who it claims to be. Plenty of phishing sites have one.
Phishing needs you to type a secret into the wrong place. Remove the typing, and you remove the attack.
Why a password manager is a quiet phishing defense
Here is a defense that works even on a distracted day, because it does not depend on you noticing anything. A password manager saves each login against the real site's domain. When you land on a page, it will only offer to autofill if the domain matches the one it has on file. On a lookalike phishing site, the domain does not match, so it stays silent.
That silence is a signal. If you are on what looks like your bank's login page and Kinship Vault does not offer the login you expect, treat that as a warning that the address is wrong. Every fill in Kinship Vault is gated by Face ID or Touch ID, and it fills into the genuine site rather than a fake one, which quietly closes the trap.
Passkeys: phishing that cannot land
The strongest answer is to remove the secret entirely. A passkey is bound to the exact website it was created for. It simply will not work on a different domain, so a fake lookalike page cannot trigger it, and there is no password or code to type, copy, or be tricked into handing over. That domain binding is what makes passkeys phishing-resistant in a way passwords never can be. Where a service offers one, a passkey is the most durable protection you can adopt, and you can learn more in our passkeys documentation.
Kinship Vault stores passkeys right alongside your logins and 2FA codes, each use gated by your face or fingerprint, so adopting the phishing-proof option does not mean juggling another app.
The bottom line
Phishing is a confidence trick, and confidence tricks beat willpower more often than we admit. So stop relying on willpower alone. Build the habit of never logging in from a link, let a password manager refuse to fill on the wrong domain, and move your most important accounts to passkeys. Do that, and the convincing fake in your inbox has nothing left to steal.
Fill only on the real site.
Kinship Vault ties every login to its genuine domain and stores phishing-resistant passkeys, all gated by Face ID or Touch ID, on iPhone, iPad, and Mac.
See how it protects your logins