I feel I'm fairly immune to traditional phishing because I never click a URL in an email. If namecheap sends me an email saying one of my domain names is about to expire, I don't use their "Renew Now" link I go to "namecheap.com" (not hard to type), log in, and renew the name. Banks and other organizations that send long complicated links in emails and encourage people to click them are part of the reason phishing is possible. These emails should look like:
Dear John Doe,
An automatic payment has been made from your checking account:
04-May-2014 $125.00 to Big Energy Utility Corp
For more details, please log on to your online banking account and click the "Recent Transactions" tab.
Yeah, part of me wonders how bad it would be / what would break if email clients banned outside links (e.g. beyond fragments in the email). My suspicion is that the only useful use of a link is a confirmation email which have other potential implementations...
plus it forces web sites to be designed in such a way to easily locate what you need, e.g. "recent transactions" shouldn't be buried deeply in the navigation tree.
Dear John Doe,
An automatic payment has been made from your checking account:
04-May-2014 $125.00 to Big Energy Utility Corp
For more details, please log on to your online banking account and click the "Recent Transactions" tab.
There is no need for hyperlinks in any of that.