LeakNix

Phishing Protection That Actually Works

Disclosure: some of the vendor links on this page are affiliate links. If you sign up through one of them we may be paid a commission by that vendor, at no extra cost to you. Prices shown are the vendor’s own and can change.

The short version: the one thing that makes a phishing attack fail outright is a login that cannot be phished. Passkeys and hardware security keys do that. Everything else, browser warnings, mail filters, security suites, catches some attempts and misses others. Below is what each layer does, in the order it is worth setting up, and where a paid tool earns its place.

One more thing before the list. If your email address is already in a breach with a password attached, the phishing you get is not random. It quotes your real password, names the service that leaked it, and arrives at the address the attacker already knows works. Worth checking whether that is your situation before you spend money on software.

How a phishing attack works, mechanically

A message arrives. Email, text, a WhatsApp from “the bank”, a calendar invite, a fake missed-delivery note. It contains a link. The link goes to a domain that looks close enough: paypa1.com, microsoft-login.support, or a long URL on a legitimate hosting service. The page is a copy of the real login form.

The old version stopped there: you typed a password, they saved it. The version that has been standard since roughly 2020 is worse. Toolkits such as Evilginx run the fake page as a live proxy to the real site. You type your password, the proxy forwards it to the real service, the real service sends a two-factor prompt, you approve it, and the proxy captures the logged-in session cookie. Your SMS code or authenticator app code did nothing, because it was relayed in real time to a genuine login.

That is why the advice below leads with passkeys and not with “turn on 2FA”. Two-factor codes raise the bar. Passkeys remove it.

Layer 1: make the login itself unphishable

Passkeys

A passkey is a cryptographic key pair stored on your phone or computer. When you sign in, the site sends a challenge and your device signs it, and the signature is tied to the site’s real domain. A lookalike domain gets a signature that is useless to it, and a proxy in the middle gets nothing it can replay. Google, Apple, Microsoft, Amazon, PayPal and most large banks support them now. Set one up on your email account first, because email is what resets every other password you have.

Hardware security keys

A YubiKey or similar does the same origin-bound signing, on a device that never leaves your keyring. It is the option for people who are personally targeted: journalists, executives, anyone holding crypto. For most people a passkey in iCloud Keychain, Google Password Manager or a password manager is the same protection with less to lose down the back of the sofa.

Where authenticator apps and SMS fit

Keep them on any account that does not offer passkeys yet. They stop the attacker who only has your leaked password and is trying it from their own machine, which is the most common attack by a wide margin. They do not stop the proxy attack above. Of the two, an app is better than SMS, because SMS can also be taken by convincing your carrier to move your number to a new SIM.

Layer 2: the free protections you already have

Before buying anything, check that these are on. Between them they block the majority of mass phishing, and they cost nothing.

  • Your password manager’s autofill. This is the most underrated phishing defense there is. A password manager fills credentials only on the domain it saved them for. If you land on paypa1.com and the manager offers nothing, that silence is the warning. Train yourself to notice it rather than typing the password by hand. See our password manager comparison if you do not use one.
  • Browser safe-browsing warnings. Chrome, Edge and Firefox check URLs against Google’s Safe Browsing list; Safari’s “Fraudulent Website Warning” uses the same list. Chrome’s Enhanced Protection setting checks in real time instead of against a cached list, which catches newer pages. It is in Settings, Privacy and security, Security.
  • Your mail provider’s filter. Gmail and Outlook stop most mass phishing before you see it. What gets through is the targeted kind, which filters are worse at. Do not turn filtering down because a legitimate mail was once caught.
  • Unknown-sender filtering on your phone. iOS (Messages, Filter Unknown Senders) and Android (Messages spam protection) route texts from numbers not in your contacts into a separate list. Delivery and bank scams by text mostly arrive from numbers you have never seen.
  • The habit that beats all of them. Do not use the link. If a message says your account has a problem, open the app or type the address yourself. A genuine problem will be visible when you get there. A fake one will not.

Layer 3: what a paid security suite adds

A suite adds URL filtering across every app, not only the browser, so a link opened from a mail client, a messaging app or a PDF is checked too. Several now include a place to paste a suspicious message and get a verdict. That is useful for people who get a lot of these, or who look after relatives who do. It is not a substitute for the two layers above, and no vendor’s filter catches a page that went live an hour ago.

Kaspersky is not listed. The US Commerce Department banned the sale of its software in the United States from July 2024 and it stopped delivering updates to US customers that September. Whatever you think of the reasoning, an anti-phishing product that cannot update its blocklists is not one.

Bitdefender

Price varies by device count and term. Check the vendor

Bitdefender's Total Security bundle filters web traffic in every browser and app, flags fraudulent pages before they load, and includes Scamio, a chat-style checker you can paste a message, link or screenshot into. It is the one we point people to for the whole household, largely because the filtering runs on phones as well as computers and the price per device is low when you buy for several.

  • URL filtering across all browsers and apps
  • Anti-fraud page detection
  • Scamio message and link checker
  • Windows, macOS, Android and iOS
  • Includes a password manager with domain-bound autofill

Norton 360

Price varies by tier. Check the vendor

Norton 360 covers the same ground with Safe Web filtering and adds Genie, a scam checker that reads a pasted text or screenshot and tells you whether it looks like a known scam pattern. It bundles a VPN and cloud backup, which you may or may not want. The anti-phishing part is competent; the bundle is where the price comes from.

  • Safe Web URL filtering
  • Genie scam checker for texts and screenshots
  • VPN and cloud backup bundled
  • Windows, macOS, Android and iOS

Malwarebytes

Browser Guard is free. Premium is paid

Malwarebytes Browser Guard is a free browser extension that blocks phishing and scam pages, and is worth installing on its own if you do not want a full suite. Malwarebytes Premium adds the same filtering system-wide plus its malware engine. It is lighter than Bitdefender or Norton and the interface gets out of the way, which matters if you are installing it for someone else.

  • Browser Guard extension, free
  • System-wide web protection in Premium
  • Malware and ransomware engine
  • Windows, macOS, Android and iOS

Why a leaked password makes phishing worse

Mass phishing is a numbers game with a low hit rate. Phishing built on breach data is different. When an attacker has your address, an old password and the name of the site it came from, the message writes itself: “We noticed a login from a new device. Your password ending in ...r3 was used.” The extortion emails that quote a real password of yours and claim to have webcam footage are the crude version of this. They work because the password is real.

The fix is to know what has leaked before the attacker uses it. A free check of your email address shows which breaches hold it and which passwords were stored alongside it. Change those first, and the quoted-password email loses its only trick. The password leak check guide explains what the result means and what to do with it.

If you already clicked

  1. Change the password for that account from a different device or browser, in case the one you used is compromised. Then change it anywhere else you used the same password.
  2. Sign out of all sessions. Google, Microsoft, Apple and most banks have a “sign out everywhere” option in security settings. This kills a stolen session cookie.
  3. Check your email account for forwarding rules and filters you did not create. Attackers add a rule that forwards everything, or that deletes password-reset mails, and it survives a password change.
  4. Revoke app passwords and third-party app access you do not recognize.
  5. If you entered card details, call the number on the back of the card, not one from the email. If you entered your Social Security number, consider a credit freeze; it is free at all three bureaus.
  6. Report the message to the company being impersonated. Most have a dedicated address (Apple: reportphishing@apple.com; PayPal: phishing@paypal.com) and the report gets the page taken down faster.

Questions people ask

Do I need anti-phishing software if I already have antivirus?

Probably not as a separate purchase. The suites above are antivirus products with phishing filters included; a standalone anti-phishing tool is mostly a browser extension, and Malwarebytes Browser Guard covers that for free. Spend the effort on passkeys and a password manager instead. They stop the attacks filters miss.

Can two-factor authentication be phished?

Codes can, by the proxy method described above. Passkeys and hardware keys cannot, because what they produce only works for the real domain. If a service offers both, use the passkey and keep the code as a fallback.

Are Macs and iPhones safe from phishing?

No. Phishing does not exploit the device; it exploits the person, and it works the same in Safari as in Chrome. What iOS does well is limit what a malicious page can do after you land on it, which is a different problem. See what iOS protects against and what it does not.

Start with what has already leaked

The phishing that gets through is the phishing that knows something about you. Find out what it could know.

Check My Email for Leaks