How to Turn On Two-Step Verification on Your Accounts
Two-step verification adds a second check beyond your password — even if someone steals your password, they couldn't get in without that second step.
Two-step verification adds a second check beyond your password — even if someone steals your password, they couldn't get in without that second step.
The most common types
- SMS code — the simplest, though the least secure of the three (vulnerable to certain specific SIM-swap attacks).
- Authenticator app (Google Authenticator, Authy) — generates temporary codes without needing a connection or depending on your mobile carrier.
- Physical security key — the safest option, requires an additional physical device.
How to turn it on (general process, varies by service)
- Go to the security settings of the account in question.
- Find "Two-step verification" or "Two-factor authentication."
- Choose the method (we recommend an authenticator app over SMS if it's available).
- Save the recovery codes you're offered — they're your lifeline if you lose access to the main method.
Warning: keep the recovery codes somewhere safe and separate from the device with the authenticator app itself — if you lose your phone without those codes saved elsewhere, you could get locked out of your own account.
Frequently asked questions
What's the most secure two-step verification method?
A physical security key is the safest, followed by an authenticator app. SMS, though simpler to use, is the least secure of the three because it's vulnerable to certain specific attacks.
What do I do if I lose the phone with my authenticator app?
Use the recovery codes most services offer when you turn on two-step verification — that's why it's important to keep them somewhere safe and separate from the phone itself.