Turn on two-factor authentication, and choose it well
In short
Turn it on for your main email account first, even before your bank: that is the account that can reset all your others. Prefer an authenticator app or a physical key to a code by text message. And write down your backup codes somewhere other than the phone that generates the codes.
Why this works
Two-factor authentication adds a proof the attacker cannot get with the password alone. Not all methods are equal: a text message depends on your number, which can be moved to another SIM card without your knowledge; an app generates the codes offline on your device; a physical key also checks the site's domain, which makes it immune to fake pages. The order in which you turn it on matters as much as the method, because an unprotected email account cancels out the protection of everything else.
Step by step
Start with your main email account
It is the account that opens the others: your services' “forgot password” feature sends its links there. Protect it before your bank, before your social media.
Choose the strongest method offered
A physical security key if the service accepts one, otherwise an authenticator app, and text messages only as a last resort. A text message is still far better than no second factor at all: if it is the only option, take it.
Keep the backup codes safe
They are for the day the device is lost or stolen. Keep them off that same device: on paper, or in a password manager you can reach from elsewhere. Backup codes stored only on the phone that generates the codes protect against nothing.
Check the recovery options
Backup email address, phone number, security questions: these are your account's back doors, and they are the first things an attacker changes. Check them when you turn the feature on, then from time to time.
The most common mistakes
- Protecting the bank and leaving the email account without a second factor.
- Giving a verification code to anyone: no service ever asks for one, through any channel.
- Approving a sign-in request to make repeated notifications stop.
- Keeping the backup codes on the device that generates the codes.
- Leaving security questions whose answers are on your public profiles.
The attacks this defeats
Official sources
Other guides · Last updated: 2026-09-02.