Account recovery is every backup route into an account when the front door fails: a recovery email address, a phone number, one-time backup codes, sometimes a trusted contact or device. It is what a service falls back on when you tap Forgot password, lose the phone that holds your login codes, or discover an attacker got in and changed your password before you could.
Most people configure these options once, in a hurry, during signup, and never look at them again. Phone numbers change. Old email addresses get closed. The phone with the authenticator app gets traded in. Then the lockout happens, the recovery link sails off to an inbox that no longer exists, and at most large services there is no human being who can step in and help. Automated recovery is often the only recovery there is.
There is a second reason to care. Every recovery option is also a door. An attacker who controls a stale recovery address, or who hijacks your phone number, can reset your password without ever knowing it. Setting up recovery properly means two things at once: making certain you can always get back in, and making certain nobody else can.
Know what your recovery options actually are
When a service needs to confirm you are really you without a password, it can only check things you registered in advance. The common options:
- Recovery email: a second address where reset links are sent. The most common method, and the most commonly stale.
- Recovery phone number: receives a reset code by text or call. Convenient, but tied to your carrier account, which has weaknesses of its own.
- Backup codes: a short list of one-time codes generated when you turn on two-factor authentication. Each works once, and no phone is required.
- Security questions: an older method still used by banks and government sites. Weak if you answer honestly, strong if you treat the answers like passwords.
- Trusted contacts or devices: some services let a person you choose, or a device you already signed in on, vouch for you.
You do not need every option on every account. You need at least two independent ones on the accounts that matter, so that losing any single thing, a phone, an inbox, a slip of paper, never leaves you stranded.
Start with your email account, because everything depends on it
Password resets for nearly everything you own flow through your main email inbox. Lose that inbox and you have not lost one account, you have lost the master key to all of them. So begin there.
Open your email provider's security or account settings page and check three things. First, the recovery email and phone number on file: are they an address and a number you still control? Second, two-factor authentication: turn it on if it is off. Third, backup codes: generate a set and store it somewhere safe, which a later section covers. If second factors are new to you, our plain-English guide to how two-factor authentication works explains the choices in a few minutes.
While you are in those settings, look at the list of devices currently signed in to the account and remove any you no longer own or use. An old tablet in a drawer that can still read your email is a recovery risk all by itself.
Pick recovery contacts that will still exist in five years
The most common recovery failure is not an attack. It is pointing recovery at something temporary.
- Do not use your work email. The day you leave the job, voluntarily or not, that inbox is gone, and every personal account that recovers through it is stranded.
- Do not use an address from your internet provider. Switch providers and the address usually dies with the contract.
- Do use a second personal address, ideally at a different provider than your main one, so a single outage or lockout cannot take down both. Sign in to it a few times a year so it is not closed for inactivity.
- Point your two addresses at each other. Each becomes the recovery route for the other, and both get two-factor authentication.
Phone numbers deserve the same skepticism. A number is fine as one recovery option, but never as the only one. In a SIM swap, a scammer talks a carrier employee into moving your number onto a different card, and every reset code you rely on starts arriving at the scammer's phone. Add a PIN or port-out lock to your carrier account, most carriers offer one under account security settings, and keep at least one recovery method that does not involve your number at all.
Treat security questions as passwords, not trivia
Your mother's maiden name, your first pet, your high school mascot: real answers to these questions sit in public records and old social media posts, and relatives, exes, and former classmates know many of them outright. If a site forces security questions on you, lie on purpose. Answer "first pet" with something like "vermilion-staple-oboe" and save the fake answer in the notes field of your password manager, right next to that site's password. A made-up answer cannot be researched, and you never have to remember it because the manager does.
Store backup codes where future you can find them
Backup codes are the recovery method people most often generate and then lose. Two storage habits work well, and using both is better:
- A secure note in your password manager. Paste the codes into the entry for that account. Bitwarden, 1Password, and KeePass all support notes, so the codes stay encrypted and searchable.
- A printed copy at home. Keep it with your passport and other important documents, somewhere you could reach even if every device you own were lost or stolen at once.
Avoid the tempting shortcuts. A screenshot in your camera roll syncs to cloud storage you may not think of as sensitive. A file named "backup codes" on your desktop is exactly what an intruder or a piece of malware searches for first. And remember that each code works once: if you spend one during a real emergency, sign in, generate a fresh set, and store it the same way.
Plan for the day your phone disappears
For most people the phone is the single point of failure. It holds the authenticator app, receives the text codes, and stays signed in to the email account. Losing it should be an errand, not a catastrophe, and that takes a little preparation:
- Turn on your authenticator app's encrypted backup or sync, if it offers one, so your codes can be restored onto a replacement phone.
- Register a second factor that is not the phone on your most important accounts: backup codes at minimum, or a hardware security key kept at home.
- Record the password for the account that backs up the phone itself. Face and fingerprint sign-in make it easy to forget a password you have not typed in years, and a new phone will demand it. Store it in your password manager.
- Enable the find-my-device feature in your phone's settings, so a lost phone can be located, locked remotely, or erased.
Do a recovery review when life changes
Recovery settings rot quietly, so certain events should trigger a fifteen-minute pass through your important accounts: changing your phone number, leaving a job, closing an old email address, ending a relationship where devices or accounts were shared, or moving to another country, since some services will not text codes across borders.
The review is the same every time. Open the security settings of your email, banking, and social media accounts and read the recovery entries carefully. Update anything stale, and remove anything you do not recognize. Attackers who briefly compromise an account often add their own recovery address or phone number so they can walk back in later, long after the password is changed. An entry you cannot explain is a serious warning sign, and our step-by-step guide on what to do if your account is hacked walks through the full cleanup.
Your recovery setup checklist
Set aside about half an hour and work through this list. The order matters: email first, everything else after.
- Open your main email account's security settings. Confirm the recovery email and phone number are current, turn on two-factor authentication, and generate backup codes.
- Save those codes in your password manager and print a copy for the drawer or safe where your documents live.
- Create or designate a second personal email address, secure it the same way, and set your two addresses as each other's recovery contact.
- Add a PIN or port-out lock to your mobile carrier account so your number cannot be moved without it.
- Repeat the recovery check for your bank, your password manager account itself, and your main social media accounts.
- Replace honest security question answers with made-up ones saved in your password manager.
- Put a note in your calendar to repeat this review once a year, and any time your number, job, or address changes.