Prevention
The Email Lockout Survival Checklist
Everyone who lands on this site mid-crisis wishes they'd spent these ten minutes earlier. Eight settings, once — and your account becomes boringly, wonderfully hard to lose. Work top to bottom; the order matters.
-
Use a password manager with a unique email password
Reused passwords are how email accounts actually fall — one breached shopping site and the same password unlocks your inbox. Generate a unique one and let the manager remember it.
-
Turn on two-factor authentication (2FA)
An authenticator app beats SMS (SIM-swap attacks are real). Any 2FA beats none.
-
Save your 2FA backup codes — somewhere that isn’t the account
Every provider hands you one-time backup codes when you enable 2FA. Store them in your password manager’s secure notes or print them. This single step defuses the most common lockout.
-
Add a recovery email address
Use an address on a different provider (Gmail ↔ Outlook), so one lockout can’t take both. Check yearly that it still works.
-
Add and verify a recovery phone number
Keep it current — the number you had two phones ago helps an attacker more than it helps you.
-
Sign in on a second trusted device
A tablet or old laptop that stays signed in is a recovery lifeline for Google and Apple accounts especially — providers trust devices more than they trust answers.
-
Set up your provider’s special recovery feature
Apple: recovery contacts + recovery key. Proton: recovery phrase (without it, a reset destroys old mail). Google: Inactive Account Manager. Microsoft: keep verified aliases. Five minutes each.
-
Do a yearly security checkup
Each provider has a one-page checkup (Google Security Checkup, Microsoft account security, Apple account settings). Put a recurring reminder in your calendar — recovery info rots quietly.
Tip: print this page (it prints cleanly) and check items off on paper. Paper doesn't get locked out.