Skip to content

Accounts  ·  Checklist

Account Recovery: Set It Up Before You Need It

Most permanent account loss is not an attack. It is a lost phone, a dead email address, or a recovery option nobody checked in six years.

People think about account security as defence against attackers. The more common failure is simpler: you cannot get in, and neither can anyone else, and the account is gone.

How accounts are actually lost

The second factor is gone. Phone lost, replaced without exporting authenticator codes, or an authenticator that deliberately does not back up.

The recovery email is dead. An address from a former employer, a university, or a provider that shut down. Password reset goes there and nowhere else.

The recovery phone number was reassigned. Carriers recycle numbers. Yours now belongs to a stranger who can receive your reset codes.

Recovery codes were saved on the device that was lost.

The account was never verified with anything. Some accounts have no recovery path at all, and support cannot help because they cannot establish who you are.

None of these involves an attacker. All of them are permanent if not fixed in advance.

The audit, once, for accounts that matter

Start with the keystone account — the email address that can reset everything else. Then finances, then anything holding payment details or irreplaceable content.

For each one, check five things:

Recovery email. Does it exist, do you control it, can you sign into it right now? An address you have not tested in two years is not a recovery option.

Recovery phone. Is it your current number? Numbers change more often than people update them.

Second factors registered. How many, and would losing your phone remove all of them?

Recovery codes. Do they exist, and are they somewhere you can reach without the phone?

Active sessions and authorised devices. Anything you no longer own should be removed.

That is ten minutes per account and it is the single highest-value security task most people can do.

What to actually set up

Two independent second factors. A hardware key plus an authenticator, or two keys, or an authenticator that syncs plus recovery codes. The test is whether losing your phone in a river leaves you locked out.

Recovery codes printed and stored physically. A drawer at home, a safe, a sealed envelope with a family member. Not a photo on the phone, not a note in the account you are trying to protect.

A recovery contact where the platform supports it — a trusted person who can vouch for you. Both major platforms now offer a version of this and almost nobody enables it.

A recovery email at a different provider than the account itself. If your primary email provider is the problem, an address at the same provider does not help.

Your own domain for email, if that suits you. It is the one arrangement that lets you move providers without changing the address everything else points at. It is more effort and it removes the single largest dependency in most people's digital life.

The things that quietly break

Employer and school addresses stop working when you leave. They are used as recovery addresses constantly and then vanish.

Phone numbers get reassigned if you let a prepaid line lapse.

Authenticator apps get replaced. People switch phones and do not think about the app that has no icon on the home screen.

Services change their recovery policies, removing options that used to exist.

Recovery codes get used and not regenerated. Most sets are single-use.

Set a reminder to re-check annually. Fifteen minutes, once a year, for everything.

When you are already locked out

Try every recovery path the service offers, including ones that seem unlikely. Some ask for details like account creation date or previously used passwords.

Use a device and location you have used before. Many services weigh familiar signals heavily in recovery decisions.

Be patient with automated recovery. Some processes deliberately impose a waiting period, which exists to protect you from someone else doing the same thing. Starting over resets the clock.

Contact support with specifics. Approximate creation date, previously used recovery details, transaction identifiers, anything only the real owner would know.

For paid accounts, payment records are strong evidence. The card used, the billing address, invoice numbers.

Accept that some accounts cannot be recovered. Services with no verified recovery information and no support channel are genuinely unrecoverable, and no amount of persistence changes that.

For people who might need to act for you

If someone would need access to your accounts if you could not manage them — illness, death, incapacity — recovery planning is a different problem.

Both major platforms support a legacy contact who can request access under defined circumstances. Most password managers support emergency access with a delay.

Setting these up takes minutes and spares people a difficult process at a bad time. It is the part of this subject people avoid thinking about and the part with the highest consequences.