Prevention

The Email Lockout Survival Checklist

Everyone who lands on this site mid-crisis wishes they'd spent these ten minutes earlier. Eight settings, once — and your account becomes boringly, wonderfully hard to lose. Work top to bottom; the order matters.

  1. Use a password manager with a unique email password

    Reused passwords are how email accounts actually fall — one breached shopping site and the same password unlocks your inbox. Generate a unique one and let the manager remember it.

  2. Turn on two-factor authentication (2FA)

    An authenticator app beats SMS (SIM-swap attacks are real). Any 2FA beats none.

  3. Save your 2FA backup codes — somewhere that isn’t the account

    Every provider hands you one-time backup codes when you enable 2FA. Store them in your password manager’s secure notes or print them. This single step defuses the most common lockout.

  4. Add a recovery email address

    Use an address on a different provider (Gmail ↔ Outlook), so one lockout can’t take both. Check yearly that it still works.

  5. Add and verify a recovery phone number

    Keep it current — the number you had two phones ago helps an attacker more than it helps you.

  6. Sign in on a second trusted device

    A tablet or old laptop that stays signed in is a recovery lifeline for Google and Apple accounts especially — providers trust devices more than they trust answers.

  7. Set up your provider’s special recovery feature

    Apple: recovery contacts + recovery key. Proton: recovery phrase (without it, a reset destroys old mail). Google: Inactive Account Manager. Microsoft: keep verified aliases. Five minutes each.

  8. Do a yearly security checkup

    Each provider has a one-page checkup (Google Security Checkup, Microsoft account security, Apple account settings). Put a recurring reminder in your calendar — recovery info rots quietly.