Skip to content

Turn on two-factor authentication, and choose it well

In short

Turn it on for your main email account first, even before your bank: that is the account that can reset all your others. Prefer an authenticator app or a physical key to a code by text message. And write down your backup codes somewhere other than the phone that generates the codes.

Why this works

Two-factor authentication adds a proof the attacker cannot get with the password alone. Not all methods are equal: a text message depends on your number, which can be moved to another SIM card without your knowledge; an app generates the codes offline on your device; a physical key also checks the site's domain, which makes it immune to fake pages. The order in which you turn it on matters as much as the method, because an unprotected email account cancels out the protection of everything else.

Step by step

  1. Start with your main email account

    It is the account that opens the others: your services' “forgot password” feature sends its links there. Protect it before your bank, before your social media.

  2. Choose the strongest method offered

    A physical security key if the service accepts one, otherwise an authenticator app, and text messages only as a last resort. A text message is still far better than no second factor at all: if it is the only option, take it.

  3. Keep the backup codes safe

    They are for the day the device is lost or stolen. Keep them off that same device: on paper, or in a password manager you can reach from elsewhere. Backup codes stored only on the phone that generates the codes protect against nothing.

  4. Check the recovery options

    Backup email address, phone number, security questions: these are your account's back doors, and they are the first things an attacker changes. Check them when you turn the feature on, then from time to time.

The most common mistakes

  • Protecting the bank and leaving the email account without a second factor.
  • Giving a verification code to anyone: no service ever asks for one, through any channel.
  • Approving a sign-in request to make repeated notifications stop.
  • Keeping the backup codes on the device that generates the codes.
  • Leaving security questions whose answers are on your public profiles.

The attacks this defeats

Official sources

Other guides · Last updated: 2026-09-02.