# Spotting Phishing — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/mfa-phishing

> Recognise phishing and let autofill act as a safety check.

## Fake pages, real urgency

Phishing messages create urgency and link to a look-alike page that collects your password. Check the exact domain, not just the logo, and never type credentials after following a link in an unexpected email or message.

## If autofill is empty, stop

A password manager fills a login only on the exact saved domain. When it offers nothing on a page that looks right, the domain may be fake. Treat that as a warning, not a nuisance.

**Quiz:** Your manager will not autofill on a site that looks like your bank. What is the safest reading?

- [ ] The manager is broken, type the password by hand
- [x] The domain may not be the real one, so check it
- [ ] The bank changed its logo
- [ ] Your internet is slow

*Answer:* The domain may not be the real one, so check it. Autofill is tied to the saved domain, so a mismatch is a signal worth investigating.

**Quiz:** Which is the best response to an urgent email asking you to "verify your account" via a link?

- [ ] Click quickly before it expires
- [ ] Forward it to colleagues
- [x] Open the site yourself from a saved bookmark
- [ ] Reply with your password

*Answer:* Open the site yourself from a saved bookmark. Go to the service directly instead of through the message, and report the email.
