Start with Identity
← Glossary
Concept

Phishing-Resistant MFA

Multi-factor methods that cannot be relayed or replayed by a phishing site, principally FIDO2 security keys and passkeys. Recommended by NIST and CISA over OTP and push.

The property that makes a method phishing-resistant is origin binding: the authenticator refuses to produce a signature for a domain other than the one that registered the credential, so a proxy in the middle gets nothing usable. Everything a human can read, type, or approve can be relayed, which is why one-time codes and push approvals are not in this category regardless of how they are marketed.

See also: WebAuthn and FIDO2, passkey, AAL, MFA vendors

Last reviewed By SWI Community TeamSuggest a correctionHow we research