The Phishing Defences I Actually Rely On
Why I Stopped Trying to Spot Every Phishing Email
I used to think the answer to phishing was getting better at spotting it. Look for the spelling mistakes, check the sender address, hover over the link before you click. I've written about all of that before, and it's still useful, but I've come round to a different way of thinking about it. Phishing emails are getting better. Some of the ones landing in my inbox now don't have a single typo, and the sender address is spoofed well enough to fool anyone glancing at it on a phone screen. Recognition alone isn't enough anymore, so I've built a set of defences that don't depend on me catching every single one.

The Filtering and Verification Habits That Actually Do the Work
Most of my defence happens before an email ever gets a chance to trick me. I keep my email provider's spam filtering switched on and I report anything suspicious rather than just deleting it, because every report trains the filter to catch the next one faster. When something does land that claims to be my bank, a delivery company, or HMRC asking me to click through and "verify" something, I don't click. I open a new browser tab and go to the organisation's website directly, or I call them on a number I already have saved, not one from the email. It takes an extra thirty seconds and it's saved me more than once. If I'm on public wifi at a coffee shop, I make sure I'm connected through a VPN like NordVPN before I log into anything, since a fake hotspot is just phishing with extra steps.
Password Managers and Two Factor Authentication as My Safety Net
The truth is, I assume I'll eventually click something I shouldn't. Everyone does sooner or later, no matter how careful they are. So the defences I actually rely on are the ones that still protect me even when a phishing email gets past my judgement. A password manager like NordPass means I'm never typing my real banking password into a fake banking page, because the autofill simply won't recognise a copycat site and won't fill anything in. That mismatch alone has tipped me off to fake sites more than once. On top of that, I've got two factor authentication turned on everywhere it's offered, so even if a password does get stolen, it's close to useless to whoever's got it without the second step too.
What I Do the Moment Something Looks Off
If I do click something I shouldn't have, or I suspect I have, I don't sit on it. I change the password for that account straight away, from a different device if I can, and I check whether the same password was used anywhere else. I also report the email, both to my provider and to Action Fraud, the UK's national reporting centre for fraud and cybercrime. Reporting feels like a small thing, but it's how patterns get spotted and how genuinely dangerous campaigns get shut down faster.
Building Defences That Don't Rely on You Being Perfect
If there's one thing I'd want a Liverpool business owner or a worried parent to take from this, it's that phishing defence isn't about becoming perfect at spotting fake emails. It's about building a setup where one mistake doesn't turn into a disaster. That means layering things: filtering, verification habits, a password manager, two factor authentication, and knowing what to do the moment something feels wrong. If you want a hand working out where your own setup has gaps, my Safety Toolkit is a good place to start, or you can get in touch and I'll walk through it with you directly.
