Why a Passkey Won't Work on a Fake Website
A convincing copy of your bank’s login page can fool you. It cannot fool the cryptography behind a passkey. Here is the small, strict rule that makes the difference.
In this story 9 sections
A passkey will not work on a fake website because it is locked to the real site’s web address. Your browser checks the domain before your device signs anything. A perfect copy of your bank’s login page sits at a different address, so your phone has nothing to offer it and no code to hand over.
That is a neat claim, and my rule is to check neat claims twice. So I went to the standards and the government guidance behind it. The short version holds up. The long version is more interesting, because the protection does not depend on you spotting the fake at all.
This explainer is for anyone who has seen a "create a sign-in key" prompt and wondered what it actually does. It covers how the cryptography works, why phishing pages come up empty, and the gaps that remain.
What Is a Passkey, in Plain Terms?
A passkey is a pair of matching cryptographic keys made when you sign up. The website keeps the public key. Your phone, laptop or hardware key keeps the private key and never shares it. To sign in, the site sends a random challenge, your device signs it, and the site checks the signature.
The rules for this live in a web standard called WebAuthn, short for Web Authentication. The World Wide Web Consortium (W3C) published WebAuthn Level 3 as a full W3C Recommendation on August 25, 2026. The spec says the private key is expected never to be exposed to any other party, "not even to the owner of the authenticator."
That last line surprised me the first time I read it. You cannot copy your own private key out and paste it anywhere. Which means a scammer cannot talk you into doing it either.
Why a Fake Website Gets Nothing
The trick is a small, strict rule called scoping. When you create the credential, it is tied to the site’s identity, which WebAuthn calls the Relying Party ID. In practice that is the domain, such as yourbank.com. The W3C spec says only that Relying Party can use the credential.
Now picture a phishing page at yourbank-secure-login.com. It looks right. The logo is perfect. You are tired and you click. With a password, that is game over, because you type the secret into the fake form.
With a passkey, your browser does the checking for you. It reads the real address of the page, not the logo. That address does not match the domain the credential belongs to, so the browser never asks your device to sign. The fake site gets no signature, no code and no secret to replay elsewhere.
This is the part I find quietly brilliant. Most anti-phishing advice asks people to be perfect at spotting fakes. This design moves that job from your eyes to your browser, which reads every character of the address and never gets tired.
How Are Codes Different From a Passkey?
Codes are different because they are just numbers a person can read and retype. If a fake page asks for your six-digit code, you can type it in, and the attacker can pass it to the real site within seconds. The private key never appears as something you can type, so there is nothing to relay.
The Cybersecurity and Infrastructure Security Agency (CISA) describes exactly this attack in its fact sheet on implementing phishing-resistant MFA. A user visits a site that mimics a real login portal. They submit a username, a password and the 6-digit code from their authenticator app. All three go straight to the attacker.
CISA ranks the options from strongest to weakest. FIDO and WebAuthn sign-in sit at the top, labeled "the gold standard." App codes and push prompts with number matching come next. CISA calls those the best fallback for small businesses that cannot switch yet, but still lists them as vulnerable to phishing.
CISA is also clear on one point that gets lost in the hype. Any form of multifactor authentication is better than none. If a code is all an account offers, keep using it.
The Other Ways Codes Leak
Phishing is not the only weakness of codes. A few other attacks target the delivery route rather than the person. The CISA fact sheet lists these threats.
- SIM swap. A scammer convinces your carrier to move your number to their SIM card.
- SS7 abuse. Flaws in old phone network signaling let attackers grab texted codes.
- Push bombing. A flood of approval prompts until someone taps Accept to make it stop.
The Federal Trade Commission (FTC) makes a similar point in its consumer guide to using two-factor authentication. It warns that texted codes can be intercepted through SIM swaps. It calls authenticator apps safer, and security keys the strongest option, because they use encryption and "don’t use credentials that hackers can steal." Your phone’s built-in credential works on the same principle as those security keys.
Where Your Passkey Actually Lives
Early security keys were small USB sticks. If you lost the stick, you lost the key. Most of today’s versions work differently. They sync through your Apple, Google or Microsoft account, or through a password manager, so the same credential is available on your phone and laptop.
Syncing raised a fair question for security people. If the key can be copied between devices, is it still safe enough? The National Institute of Standards and Technology (NIST) answered that in a supplement on syncable authenticators, published April 22, 2024. It gives federal agencies guidance on using credentials that sync between devices.
The trade-off is simple to state. Synced keys are easier to live with and survive a lost phone. Device-bound ones, like a hardware key, are harder to lose control of but easy to lose outright. For most people, synced is the sensible default. Journalists, administrators and other high-value targets may want a hardware key as well.
How Common Are Passkeys Now?
The technology has moved well past early adopters. In a survey released on May 7, 2026, the FIDO Alliance, the industry group behind the standards, estimated that about 5 billion passkeys are in use worldwide. The survey, run by Sapio Research in April 2026, covered 11,000 consumers across 10 countries.
The same survey found 75% of consumers had turned one on for at least one account. Only 49% said they use one regularly when it is available. That gap matches what I see in our own inbox. Readers have made one, often by accident, then fall back to the password out of habit.
Workplaces lag too. The FIDO Alliance found that 57% of organizations still rely on phishable methods for employees’ main daily sign-in. The tech exists. The rollout is the slow part.
What Passkeys Do Not Fix
This approach closes one door very firmly. They do not lock the whole house. Attackers have already shifted to the routes this protection does not cover.
The biggest is account recovery. If a service lets anyone reset access with a texted code or a few personal questions, a scammer can skip the key entirely. Malware on your own device is another gap, since it can ride along with a session you started. So is plain persuasion, such as a fake support agent asking you to approve a new device.
There is also the small matter of passwords that still exist. Adding the new sign-in method does not always delete your old password. If the password stays active and weak, it remains a way in. Check each account’s security settings after setting one up.
None of this makes the technology less useful. It just means the fight moves somewhere else, which is how security always works. If you like seeing the machinery under other everyday web features, our How Things Work Online section collects more of these explainers.
Setting Up Your First One Without the Headaches
The easiest way to start is with the accounts that matter most. The FTC suggests beginning with email, banking and social media. Your email account deserves first place, because it is usually the reset route for everything else.
- Pick one home for your keys. Use the platform you already live in, or one password manager.
- Add a passkey to your email first. Look under security or sign-in settings.
- Keep a backup method. A second device or a hardware key avoids a lockout.
- Review recovery options. Remove old phone numbers and weak security questions.
Expect a little friction at first. Some sites hide the option deep in settings, and the prompts look different on every platform. That confusion is its own small digital-life mystery, and our Digital Life section covers more of the odd ways phones and apps nudge us.
The Bottom Line on Passkeys and Fake Sites
A passkey stops phishing by refusing to work anywhere but the real domain. The check is done by your browser and your device, not by your eyes. That is why a flawless fake login page still comes up empty.
It is not magic. Recovery flows, malware and social engineering still matter. But if an account offers you one this week, take it, start with email, and keep a backup way in.
Can a passkey be phished?
What happens to my passkeys if I lose my phone?
Is a passkey safer than a text message code?
Does the website store my fingerprint when I use a passkey?
In this story 9 sections
Keep Reading
All storiesThe Odd List · Fridays