Phishing: How to Recognize and Avoid Attacks

Every day, 3.4 billion phishing emails are sent worldwide. Behind these messages lie increasingly sophisticated manipulation techniques. Understanding how they work is the best way to protect yourself.

What is phishing and why does it work?

Phishing is a fraud technique that involves impersonating a trusted organization (a bank, delivery service, or government agency) in order to steal personal information. Its effectiveness rests on a simple principle: the appearance of legitimacy.

A phishing email replicates the logos, colors, and tone of an official message. Users rely on visual appearance to judge whether a message is trustworthy — and that habit is exactly what attackers exploit. Whether by email, SMS, or even postal mail, the mechanics are the same: create a convincing appearance to trigger a hasty action.

How do attackers create a sense of urgency?

Phishing messages use psychological pressure to bypass critical thinking and push people to act quickly, before they have time to reflect. The goal is to provoke an emotional reaction rather than a rational analysis.

The most common pretexts follow a recurring pattern:

  • "Suspicious activity detected on your account — change your password immediately"
  • "Payment issue — your subscription is about to be canceled"
  • "Package on hold — customs fees due within 24 hours"
  • "Security alert on your credit card"

Each message contains a link or button leading to a fake site that looks visually identical to the real one. That's where victims enter their credentials, believing they're logging into the legitimate service.

How do you spot a fake domain name?

The most reliable way to identify a phishing site is to read the URL carefully — and specifically the domain name. Attackers use several disguise techniques to fool the eye.

Let's use example.com as the legitimate domain:

  • Subdomain abuse: example.another-dangerous-site.cam — the real domain here is another-dangerous-site.cam, not example
  • Misleading hyphen: example-secure-login.cam — an entirely different domain that contains the brand name
  • Different TLD: example.site instead of example.com
  • Typosquatting: examplle.com — a doubled letter that's easy to miss when reading quickly

The rule to remember: the real domain is what appears just before the TLD (.com, .org, .net). Everything to the left of an additional dot is a subdomain, which anyone can create.

Can you verify the authenticity of an email?

Yes, but not by relying on appearance alone. Spam filters catch some fraudulent emails using technical mechanisms like SPF and DKIM, which verify that an email was actually sent from an authorized server for the displayed domain.

SPF (Sender Policy Framework) lists the servers authorized to send emails for a given domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature that the recipient can verify. This information is visible in the message's technical headers.

But these mechanisms have an important limitation: they prove the technical origin of the domain, not the actual identity of the sender. An attacker can configure perfectly valid SPF and DKIM records on a domain like support-security-amazon.com. It's technically clean — but humanly deceptive.

Why is SMS phishing even more dangerous?

Smishing (SMS phishing) exploits the specific characteristics of mobile devices to bypass users' natural vigilance. SMS is often perceived as more trustworthy than email, even though the protections are less effective.

Several features make SMS particularly risky:

  • Spam filters are less effective than on email
  • The mobile interface doesn't display the full URL before you tap it
  • The sender number can be replaced by an alphanumeric name (UPS, IRS) that's easy to spoof
  • The URL in a mobile browser is often truncated
  • A fraudulent message can appear in the same conversation thread as genuine messages from the same sender

The pretexts mirror those used in email phishing: packages on hold, bank alerts, pending refunds, government notices.

How does a password manager protect against phishing?

A password manager compares the actual URL of a site against the one stored for each set of credentials. If the domain doesn't match exactly, it won't offer to fill in the fields. It's a passive layer of protection that requires no effort from the user.

Where the human eye might confuse example.com and examplle.com, the password manager performs a strict, character-by-character comparison. It's not fooled by visual domain disguise tricks. This automatic verification acts as a safety net in everyday use: if the password manager doesn't offer your credentials on a site, that's an immediate red flag.

Why isn't 2FA enough to stop phishing?

Two-factor authentication (2FA) is a genuine security improvement, but it does not protect against real-time automated phishing attacks. In what's known as an AiTM (Adversary-in-the-Middle) attack, the attacker intercepts and relays each step of the login process.

Here's how it works: the victim enters their credentials on the fake site. The fake site immediately forwards them to the real site, which sends a 2FA code. The victim enters that code on the fake site, which relays it in turn. The attacker ends up logged in with a valid code — in real time.

2FA remains effective against delayed attacks — a stolen password database becomes useless if 2FA is active. But against a real-time proxy, the one-time code is intercepted before it expires.

Do passkeys protect against phishing?

Yes. Unlike a password + 2FA code combination, a passkey is cryptographically bound to the exact domain for which it was created. On a fake site — even one that looks visually identical — the passkey simply won't activate.

There's nothing to intercept and nothing to replay: authentication is based on a cryptographic exchange between the user's device and the legitimate server. Even a real-time AiTM proxy can't bypass this protection. Passkeys represent a structural solution to phishing, by eliminating the weak link — the shared secret that a user can unknowingly hand over.

Should you lie on security questions?

Security questions ("What's the name of your pet?", "What city were you born in?") often cover semi-public information. An attacker with access to your social media profiles, a data breach, or even a passing familiarity with you can answer them on your behalf.

There's nothing stopping you from lying. "What is your favorite animal?" can receive the answer "the planet Mars." The key is being able to retrieve that fake answer — a password manager is the natural place to store it, just like any other password.

Key takeaways

  • Phishing relies on the appearance of legitimacy and a sense of urgency: slowing down before you click is the first habit to build
  • The URL is the only reliable indicator: learn to read the actual domain name, especially on mobile
  • A password manager checks the URL for you and won't be fooled by fake domains
  • 2FA protects against delayed attacks, but not against real-time phishing
  • Passkeys are the only structural protection that makes phishing technically impossible
  • Lie on security questions and store your fake answers in a password manager

Beyond good individual habits, protecting your data also depends on the platform you choose. Discover our approach to security and data sovereignty.

Free signup

No credit card. Sign up in 1 minute

Boost your productivity starting today. Sign up and try for free.

We use your email and name
to create your Octopussian workspace.

or
@ Continue with my email

We respect your privacy. Your information will not be used for any other purpose.
By signing up, you agree to our Terms and Conditions and Privacy Policy