You cannot guarantee "completely unphishable", only that you cannot yet conceive of a way to do it. It's very dangerous to assume that something is completely secure.
WebAuthn binds the credential to the domain. Under the assumption that your web browser and security key is operating according to spec this is unphishable. If your web browser or key contains a bug, or the domain is breached then all bets are off anyway.