The one idea
Everything practical in this cursus reduces to a single principle, and it is worth stating before any of the detail.
An attacker controls the channel they contacted you on. If they emailed you, they control that thread and any reply address in it. If they called, they control that number and anyone who answers a callback to it. If they set up a video call, they control who appears on it. If they messaged you on a platform, they control that account.
Therefore any verification performed inside that channel verifies nothing. Replying to ask are you sure, calling the number in the signature, or asking the face on the screen to confirm they are real are all questions routed to the attacker, who will answer yes.
Out-of-band verification means confirming through a channel you established independently. A number you already had, from your own records or the corporate directory. A separate messaging system. Walking to someone's desk. Calling the organisation's published switchboard rather than a number you were given.
The reason this defence is durable, unlike every detection-based approach, is that it never examines the message. It does not matter how convincing the email is, how accurate the voice is, or how many synthetic colleagues appear on the call. The check happens somewhere the attacker is not.
Generation can improve without limit and this still works. That property is rare in security and it is why the rest of this lesson is about making the habit reliable rather than about improving anyone's judgement.

