CYBER WELFARE

Protect your Digital Privacy

Anti-phishing technologies: what exists and what each one is for

An email with your bank’s logo, the right colours, a polite tone and a button: “Verify your details”. Messages like this reach a great many people, including people who have never banked there, and they rely on one simple gesture: opening the link and typing your login details into a page that imitates the real one. This is phishing (a message that pretends to come from a trusted sender in order to get data or money), and in its banking form it goes straight for your account.

The first line of defence is still a habit: never use an email as your way in to the bank. Alongside that habit, though, a whole range of technologies are at work, many of them already switched on: filters that set fake messages aside, checks on who really sent an email, apps that ask you to approve every payment, and credentials that simply refuse to be handed to a fake site.

This post lays out the main anti-phishing technologies one by one, with their real advantages and limits, without pointing to any specific product. It is the technology side of the recommendation on emails pretending to be your bank: the tools work best when they support that rule of behaviour, not when they replace it.

How to read this list

First, the mechanism in a few lines. To succeed, a bank phishing email has to clear three hurdles: reach your inbox, persuade you to open a link, and obtain something that actually works — a password, a code, a payment authorisation. Each technology in this list steps in at one of those points; none of them covers all three, which is why it makes sense to combine them.

The technologies are organised into four functions, the same ones used in the post on what to do after a bank phishing email:

  • prevention — stopping the email from arriving, or the attempt from succeeding;
  • detection — noticing that something is wrong, even after the fact;
  • response — stopping the damage and regaining control;
  • governance — keeping things in order over time, especially when more than one account or person needs protecting.

For each one you’ll find the risk it reduces, its advantages, its honest limits, and how complex it is to use.

1. Prevention technologies

Spam and phishing filters

Systems run by your email service that analyse incoming messages and move suspicious ones into the junk folder.

  • Risk reduced: fake emails reaching your main inbox.
  • Advantages: they work automatically; they learn from what users report; they stop most messages sent out in bulk.
  • Limits: some fake emails still get through, especially well-crafted ones; now and then they catch legitimate messages too. An email that lands in your main inbox is not genuine just because it got there.
  • Example: a fake “security alert” from your bank ends up in the junk folder, and stays there.
  • Complexity: basic.

Handling email more generally will be the subject of a dedicated recommendation on checking emails (R17).

Sender authentication: SPF, DKIM and DMARC

Three technical checks that your email service uses to confirm that a message really comes from the domain it claims (the part of the address after the @ sign):

  • SPF — the list of servers allowed to send email for that domain;
  • DKIM — a digital signature showing that the message comes from the stated domain and hasn’t been altered;
  • DMARC — the rule the domain publishes to say what should happen to emails that fail the other two checks: let them through, set them aside, or reject them.
  • Risk reduced: emails that use exactly the bank’s address without any right to it (spoofing, or faking the sender).
  • Advantages: if the bank applies them with a strict rule, emails using its domain without permission are discarded before they arrive.
  • Limits: they don’t protect against lookalike domains: an address with one letter changed or an extra word added passes the checks, because it genuinely belongs to whoever registered it. And they don’t depend on you, but on the bank and your email service.
  • Example: an email with exactly your bank’s sender address is rejected because it doesn’t carry the right signature; another, from an almost identical domain, gets through. That’s where your habit matters.
  • Complexity: invisible to the recipient; intermediate for whoever manages a domain.

Bookmarks and the bank’s official app

The way to reach your bank without going through links: a bookmark saved in your browser with the correct address, or the app downloaded from the official app stores.

  • Risk reduced: landing on a fake page by following a link.
  • Advantages: it turns the rule “don’t click” into an automatic gesture; it works even against the most convincing emails, because the link is never used.
  • Limits: the bookmark needs to be created by typing the address yourself, not from a message or from an advert in search results; counterfeit apps occasionally appear in app stores, so it’s worth following the directions on the bank’s official website.
  • Example: you receive an email about a “pending payment”. You don’t open the link: you open the bank’s app and look. If there’s nothing there, there was nothing.
  • Complexity: basic.

Password manager

A tool that stores your passwords in encrypted form (scrambled so that only you can read them) and fills them in automatically, but only on the exact address they were saved for. It sits at the heart of the recommendation on storing passwords safely.

  • Risk reduced: entering your bank login details on a site that imitates it.
  • Advantages: it acts as an alarm bell: if the manager doesn’t offer your password on the sign-in page, the address isn’t the one you saved; it also makes a unique password for the bank easy.
  • Limits: the signal only works if you heed it: copying the password in by hand on the site “that doesn’t recognise it” cancels the protection. The manager itself needs a strong master password.
  • Example: you open a link, the page looks identical to your bank’s, but the manager stays silent. You close the tab and sign in from your bookmark: there, the password appears straight away.
  • Complexity: basic.

Strong authentication and in-app approval

The second check, on top of the password, that banks ask for when you sign in or make a payment: a temporary code, an approval in the app, a fingerprint. It is the banking version of protecting accounts with a second factor; the approval screen often shows the amount and the payee.

  • Risk reduced: use of a stolen password; payments made without your knowledge.
  • Advantages: the password alone is no longer enough; an approval showing the details on screen gives you one last moment to say no.
  • Limits: attackers know this, and try to get you to read out the OTP (the one-time passcode) over the phone, or to approve a request under some pretext. No one at your bank ever needs to hear your code.
  • Example: the app asks you to approve a bank transfer you didn’t set up. You decline and call the bank on its official number.
  • Complexity: basic.

Passkeys and security keys

Sign-in methods with no password to type. A passkey is a credential tied to your device and unlocked with your fingerprint, face or PIN; a security key is a small physical device that confirms your sign-in.

  • Risk reduced: credential phishing, even with very polished fake pages.
  • Advantages: they resist fake sites by design: the credential is tied to the service’s real address, and on a different address it simply doesn’t work.
  • Limits: not every bank offers them yet; they call for some care in managing your devices and a backup method; a physical key costs money and needs to be kept safe.
  • Example: you sign in to online banking with your fingerprint; on a fake page the same gesture produces nothing worth stealing.
  • Complexity: basic for passkeys, where available; intermediate for physical keys.

2. Detection technologies

Bank notifications and in-app messages

Automatic alerts from the app for every transaction, sign-in, new device or change to your contact details, together with the section of the platform where the bank posts its own communications. They are the banking equivalent of account login alerts.

  • Risk reduced: unauthorised transactions going unnoticed; having to judge an email on the strength of the email itself.
  • Advantages: notifications reach you without your looking for them, so you can react within minutes; the in-app message area gives you a stable place to check: if a communication is genuine, you’ll usually find it there too.
  • Limits: notifications and alerts can be imitated by text message (SMS) or email: the ones that count are those you see inside the app. If they arrive too often, people stop reading them.
  • Complexity: basic.

Browser and email warnings

The warning pages your browser shows in front of sites known to be deceptive, and the labels your email service adds to suspicious messages or to senders it couldn’t verify.

  • Risk reduced: opening a phishing page that has already been reported.
  • Advantages: they step in at the very moment the mistake is about to happen.
  • Limits: they cover known sites, not newly created ones. And the padlock in the address bar proves nothing on its own: it shows a connection over HTTPS, in other words an encrypted one, not who is on the other end. That’s why it’s worth knowing the signs of a fake bank email as well.
  • Complexity: basic.

3. Response technologies

Reporting phishing

The “report phishing” button in your email service, and the reporting channels that many banks list on their official website.

  • Risk reduced: the same message reaching other people, or reaching you again.
  • Advantages: it feeds the filters and lets the bank warn its other customers; it takes a few seconds.
  • Limits: it doesn’t undo what has already happened; the reporting address must come from the official website, never from the suspicious email.
  • Complexity: basic.

Freezing cards and features from the app

The functions that let you temporarily freeze a card, or switch off online payments or payments abroad.

  • Risk reduced: misuse of card details entered on a fake page.
  • Advantages: immediate, reversible, available at any hour.
  • Limits: they don’t replace calling the bank or reporting the matter to the police; they don’t stop transfers that have already gone through.
  • Complexity: basic.

Authorised devices and changing your credentials

The section where you can see which phones are allowed to approve transactions, together with the option to change your password.

  • Risk reduced: someone who has obtained your credentials registering their own device and carrying on.
  • Advantages: it lets you revoke anything you don’t recognise; changing the password closes the door that was used.
  • Limits: do it from your bookmark or the app, never from a link; if your contact details have been changed, you’ll need the bank’s help.
  • Complexity: basic.

4. Governance technologies

These matter when the accounts aren’t only yours: a joint account, a parent you help out, a small business.

A dedicated email address for the bank

An address used only for your bank and never published anywhere else.

  • Risk reduced: fake emails blending in with the rest of your mail.
  • Advantages: any message “from the bank” arriving at your everyday address becomes suspicious by definition.
  • Limits: it needs protecting as carefully as the bank account itself, with a unique password and a second factor; it adds one more inbox to keep an eye on.
  • Complexity: basic.

Training and awareness

Learning that explains why a bank never asks for codes by email, not just how to spot the fake message.

  • Risk reduced: mistakes made in a hurry or when tired.
  • Advantages: it makes the habit of checking through the official channel last; it is the pillar on which the Cyber Welfare Framework rests.
  • Limits: it needs to be ongoing; a one-off session has a short-lived effect.
  • Complexity: basic.

Comparison table

FunctionTechnologyRisk reducedMain advantageMain limitComplexity
PreventionSpam and phishing filtersFake emails in the inboxAutomatic, no set-upSome messages get throughBasic
PreventionSPF, DKIM, DMARCFaked senderDiscards misuse of the bank’s domainDoesn’t stop lookalike domainsInvisible
PreventionBookmarks and official appFake pages opened from a linkThe link is never usedMust be set up with careBasic
PreventionPassword managerCredentials given to a fake siteWon’t fill in on the wrong addressUseless if you copy by handBasic
PreventionIn-app approvalStolen password, unwanted paymentsShows what you’re authorisingThe code can be talked out of youBasic
PreventionPasskeys and security keysCredential phishingNothing to hand overNot yet widely supportedBasic / Intermediate
DetectionNotifications and in-app messagesUnnoticed transactionsReaction within minutesCan be imitated outside the appBasic
DetectionBrowser and email warningsAlready reported pagesStep in at the right momentDon’t cover new pagesBasic
ResponseReportingSpread of the messageHelps others tooDoesn’t repair damageBasic
ResponseFreezing cards in the appMisuse of card detailsImmediate and reversibleDoesn’t stop completed transfersBasic
ResponseAuthorised devicesLingering accessRevokes what you don’t recogniseNeeds the bank if contacts changedBasic
GovernanceDedicated email for the bankFake emails blending inMakes everything else suspectOne more inboxBasic
GovernanceTrainingMistakes in a hurryA lasting habitNeeds continuityBasic

How to choose

If you’re an individual. Official app or bookmark, bank notifications switched on, in-app approval for every payment. These are often already available and cover the largest share of the risk. Add a password manager, and passkeys wherever your bank offers them.

If you help a family member. Create the bookmark together, or install the app from the official app stores; turn on notifications and a spending limit for transfers; agree on one simple rule: “we never reach the bank from an email, and no one ever needs our codes over the phone”.

If you run a small business or a charity. Keep a separate address for banking, require a second check for transfers to new payees, set up SPF, DKIM and DMARC on your own domain so that no one can send email in your name, and set aside regular time for training.

A rule of thumb. No single technology stops every attempt. Among anti-phishing technologies, the combination that gives the best result for the effort involved is access only from the app or a bookmark + in-app approval + notifications switched on. Filters reduce the number of fake emails you see; this combination reduces what the ones that get through can achieve.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsKnowing what each anti-phishing tool does for your banking, and what it cannot do
AwarenessRecognising that a filter, a padlock or a logo are not enough to show that a message is genuine
Secure BehaviourAlways reaching the bank through the official channel, and letting technology support that habit

Reference level: FL3 — Autonomous. This is the level at which you understand a tool well enough to set it up without help and to read the signals it gives you correctly.

Conclusion

Against bank phishing, technology does a great deal, often quietly: it filters, checks, warns and asks for approval. But every tool stops at the same point: the moment a person decides whether to open a link or read out a code. If you’d like to know where to start, the digital resilience self-assessment gives you a reference point.

What to do next. Today, open your bank’s app and check which notifications are switched on; then create a bookmark for online banking by typing the address yourself.

Related content

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.