Skip to main content
May 15, 2026
Question

Feedback: Phishing prevention

  • May 15, 2026
  • 31 replies
  • 184 views

This suddenly started appearing on my various computers in the 1Password Chrome extension.

Now I have to click twice every time to copy a username or password.

Please either disable this immediately or provide a checkbox to turn it off.

Thank you!

 

31 replies

1P_Travis
1Password Employee
1Password Employee
May 19, 2026

Hey! Looks like a bug that the existing setting to turn this off isn't working. We're on it.

However, is there a reason you want to turn it off? Also this prompt primarily shows when you copy details on a login that doesn't have the proper URL on it. Is there a reason you don't want to add a URL to those logins? Are they not used for autofill?

Thanks!

May 19, 2026

This is really annoying that this started doing this. I hope this gets patched and fixed immedately.

Just because I have a tab open and I click copy on an entry does not mean I am on a page even remotely related to the credentials itself. I shouldn't get any warnings or I should have the ability to turn these annoying popups off. These are not used for autofill and shouldn't be prompted to be saved. Now I have to dismiss an extra popup every time I click copy on an entry? Please fix this. 

For context, we often just use the browser extension to find an entry, the entry doesn't even necessarily need to be for something on the internet (e.g. environment variables, password to an application on the computer, username for logging into a remote computer, etc.). These types of things will and should never be prompted to be saved.

This is the pop up for your reference:

1P_Travis
1Password Employee
1Password Employee
May 19, 2026

Interesting - do you use the desktop application at all or just the browser extension?

We'll be shipping a fix for the setting to turn this off shortly. Should help your use case either way. Cheers!

May 19, 2026

I should add the missing URLs, but I have thousands of logins and sometimes just need to log in quickly.

1P_Travis
1Password Employee
1Password Employee
May 19, 2026

Gotcha, thanks for the context. In some cases we'll actually give you a quick way to add the URL is it's on our verified list. Should help for your logins on most popular websites and overall be faster than a copy.

We were able to find the bug and getting the fix up now for the setting. Thanks for your feedback!

August 10, 2026

In many cases I do not want to add a website. https://10.0.1.177 is my scanner that I’m trying to paste into now, but next boot it might grab https://10.0.1.178 from dhcp, etc. I don’t need a nanny, I need a place to securely store credentials.

May 19, 2026

Thank you! Always good to have options.

July 16, 2026

This has started popping up for me in the last week or so. I like others want a setting to turn this off.

There is a good reddit thread that indicates the reasons for disabling this option here: This is annoying : r/1Password

My guess is this is supposed to help, but there are many cases where you are just using the browser extension to lookup a password to copy/paste to another window (VPN client, etc) that will never have a website URL and it just becomes annoying.

It never use to do this and started after the most recent 1Password browser extension update.

1P_Travis
1Password Employee
1Password Employee
July 16, 2026

Heyo! As others have mentioned, this prompt will show whenever the URL you're on is not added to any login you have stored in 1Password. This is similar to an earlier phishing prevention prompt we released in January and the setting to turn it off is the same - from the browser extension right click the 1Password icon > Settings > Notification > Warn about potential phishing.
 

 

July 16, 2026

Excellent, thank you!!!

July 20, 2026

I was having the same issue and found this topic. I think the wording of the setting is slightly misleading. I took it to mean that it would alert or stop me if, for example, I pasted my paypal details into a site like paypaal. Instead if I try copying credentials from the chrome app as I use different browser windows it pops up the ‘unrecognised website’ warning which becomes pretty annoying pretty fast. I had enabled this setting for my company’s users as it is useful as a phishing prevention measure, but it gets in the way if they are on one site and need to copy out the credentials to another site.

 

 

1P_Gem
1Password Employee
1Password Employee
July 21, 2026

Thanks for the feedback ​@knightknight! I can understand how this setting could be better clarified, and how it could become frustrating quite quickly if copying and pasting credentials between browser windows is a regular part of your workflow.

 

If you have any ideas for how it could work better for you, such as a less intrusive warning, or an additional option that limits alerts to sites that are visually similar to the stored URL, I'd be happy to file a feature request with the team on your behalf. Just let me know!

July 21, 2026

Hi, the setting says it will alert when login details are pasted into a site that is not saved in 1Password, but instead it is triggering when credentials are being copied, so there is an inconsistency between what it does and what it is meant to do. I can see a use case for the message if I land on a paypaal phishing page, 1Password does not automatically paste in my paypal details, and I try to force it to do so by clicking the Autofill button. Aside from that though there are many legitimate reasons why a user would want to copy a username or password out of 1Password and the alert would be just getting in their way.

 

1P_Gem
1Password Employee
1Password Employee
July 22, 2026

Hi ​@knightknight, thanks for the feedback! I’ve filed this with the team to look into how we can improve on this moving forwards.

July 27, 2026

Just to bump this thread, my 1pass browser extension just started doing this today.

I dislike this greatly.

I can see that you have instructions for disabling this warning, but I still think you need to know that this feature is misjudged.

I don’t think my use profile for 1pass is that unusual. I have it installed on a work machine and home machines.

In many cases, I will open the browser plugin to get a password for X, Y, or Z environment / firewall / application that I have open remotely.

It is of no consequence that the browser window I am getting it from is pointed elsewhere. I have spent 9 minutes of my morning registering for these forums to come and tell you this, which should be an indication of how irritating I find you enabling this feature without prompting :)

I love your product otherwise.

1P_Dave
1Password Employee
1Password Employee
July 27, 2026

​@owen_hughes 

Thank you for the feedback! Trying to trick users into copying and pasting their login credentials into a malicious website is a common phishing technique, and 1Password's Phishing Verification feature adds another layer of protection to help guard against these attacks.

That being said, as you mentioned, if the feature doesn't fit your workflow you can absolutely turn it off in Settings > Notifications. > Warn about potential phishing.

In many cases, I will open the browser plugin to get a password for X, Y, or Z environment / firewall / application that I have open remotely.

Out of curiosity, is there a reason why you don’t use Quick Access to grab credentials for apps outside of the browser instead? You might find it a bit faster: Get to know Quick Access

-Dave

August 21, 2026

I’ve actually done the same thing as Owen - got so fed up with the unrecognized website warning that I also spent 10 minutes creating an account just now to tell you this.

 

For my work I’m often working in numerous preview environments, where the URL isn’t neccesarily the same as the main staging environment (think… feature-name-app-name.web.app is the build name, but staging.app.name is the staging environment -- all of the preview builds point to the staging backend, but the urls are always going to be different), but I just want to copy the login to the test account to log into that preview build of the day. every single time I do this I get the unrecognized website warning and it’s just about made me frustrated enough to tear my hair out. (it’s actually made me contemplate giving up and just keeping a list of frequently used passwords and emails on my desktop, which is… defeating the entire purpose of using 1password + is HORRIBLE security wise. Using the product should not make me want to give up on the entire purpose lol)

 

I get that y’all are trying to point us towards the quick access - I have never used quick access and because I’m working primarily within a browser and the 1password extension, I don’t want to learn a new way of accessing a login. I actually rarely even use the desktop app, I much prefer how the browser extension is directly within the context of the work I’m doing on my browser. 

 

I’ve turned it off now, thanks for this thread!

August 16, 2026

Feature request: Per-item exception for phishing/unrecognized website warnings

I have an admin Login that is intentionally used across many unrelated domains. I want to keep the phishing/unrecognized website protection enabled globally because it's valuable for all my normal Login items.

Could you add a per-item option such as “Allow this login to be used on unrelated websites without warning”?

This would let intentionally domain-agnostic credentials opt out without weakening phishing protection for every other credential.

1P_Dave
1Password Employee
1Password Employee
August 17, 2026

​@dreamweaver 

Thank you for the feedback! Would using Quick Access to copy the password for that login item instead of copying from the browser extension fit your workflow: Get to know Quick Access

-Dave

August 21, 2026

​@1P_Dave I can use it but it also seems a but unwieldy. I am in a browser. The extension icon is right there. Instead I have further to move the mouse, more things to click and then type. Of the two my preference is the extension with the extra click of copy anyway.

 

I think the phishing/unrecognized website warning is awesome and I would like to leave it on but I would just like to turn it off for this one entry.

 

I have considered that up until a couple of weeks ago I did not have this protection so I should just turn it off globally, but like I said it is a great feature I’d like to keep on, EXCEPT for this one entry out of hundreds.

 

Thanks

October 1, 2026

Indeed, this "feature" is an extremely rare misstep from 1Password. This is such a great application and service, but this feature was extremely misguided.

A much better implementation might have been to have it off by default and, the first time it occurs, have some kind of dialog to introduce the feature with an option to turn it on, as many people have mentioned. We are the ones who manage the passwords in our system and when and where we want to use them. If I've actively pressed the copy button, that means I want to copy the password. This is great for avoiding unintended autofills, but for me, the most time I need to manually copy is when 1Password won't fill it in automatically for me: things like remote desktop logins and other application logins that 1Password doesn't pop for.

If the product worked flawlessly, there'd be less need to manually copy passwords. I, too, was fooled by the messaging. Something along the lines of "avoid copying unrecognised websites" doesn't define what "unrecognised" means. Perhaps "phishing website" or "spoof websites" might be more accurate, but a legitimate website being unrecognized by 1Password, does that mean you have to be introduced to every single website on the planet? Phishing is most often done from spoof websites, which 1Password should be able to recognize, but leave legitimate websites alone. 

Perhaps in the future, before turning on such a disruptive workflow feature, you might canvass the user base or default the feature off. 

1P_Dave
1Password Employee
1Password Employee
October 1, 2026

​@STAME 

Thank you for the feedback! You wrote: 

If I've actively pressed the copy button, that means I want to copy the password. 

To clarify, this feature is designed to protect you if you fall victim to a phishing attack and are tricked into entering or pasting your password into a malicious website impersonating the legitimate one. It provides an additional layer of protection by warning you when the website you’re visiting isn’t linked to the login item you’re using.

The warning isn’t triggered simply because 1Password doesn’t recognize a website. It appears when the website isn’t one of the sites linked to your login item. If it’s a legitimate site where you’d like to paste your password in the future, you can add it to the login item to avoid seeing the warning.

If you personally don’t need the feature then you can turn it off: 

  1. Open your browser.
  2. Right-click on the 1Password icon in your browser's toolbar and click Settings. 
  3. Click Security & privacy. 
  4. Turn off the Phishing Prevention features. 

I hope that helps. 

-Dave

October 1, 2026

Thanks Dave - but I still don’t understand.

I am in a Windows app doing windows thing.
For whatever reason, 1P does not pop in Apps, only websites, so I move my mouse to the 2nd screen where the 1P extension sits there waiting for me.
I find the login I need and press the copy button.
I shoot back to the app to paste in the stored password only to find that the p/w was never copied and there is a message in the extension instead.

I’m not sure anyone refers to that as phishing.  Phishing (as others have put it in this thread) is using my PayPal login on a website called www.paaypal.com or www.p@ypal.com.

Does 1P have actual phishing protection that I am going to go without if I turn this off or is phishing considered “you have copied a password when you weren’t on that site”.

Thanks.