HomeSecurity › Turning on two-step verification

Padlock on a keyboard, digital security concept

How to turn on two-step verification for your accounts

Updated in 2026 · 5 minute read

A password, no matter how long and complex, can end up in the wrong hands: through a data leak at a service, a phishing link, or simply because you reused it somewhere unreliable. Two-step verification is the most effective way to keep your account safe even if that happens. Here we explain what it is, what options exist, and how to turn it on.

Before you start: always turn on two-step verification from each service's official settings (for example, myaccount.google.com for Google). Be wary of any message asking you to "verify your account" through an external link: it's usually a phishing attempt.

In this article:

  1. What two-step verification is and why it protects you
  2. SMS, authenticator app, or physical key: the most common types
  3. How to turn it on step by step for a Google account
  4. Why it's better to use an authenticator app instead of just SMS
  5. Keep your backup codes somewhere safe
  6. What to do if you lose access to your second factor

1. What two-step verification is and why it protects you

Two-step verification (also called 2FA, two-factor authentication, or "double factor") adds a second check on top of your usual password. The idea is simple: the password is "something you know," but the second step also requires "something you have," like your phone, or "something you are," like your fingerprint.

This means that if someone gets hold of your password — for example, because you used it on a website that suffered a data leak, or because you fell for a phishing email — they won't be able to get into your account without that second element. It's the difference between a stolen password being a minor scare or a real problem with your email, photos, or banking compromised.

2. SMS, authenticator app, or physical key: the most common types

Not all two-step verification methods offer the same level of protection. The three most common are:

For everyday use, an authenticator app offers the best balance between security and convenience, and it's the option we recommend if your account allows it.

3. How to turn it on step by step for a Google account

  1. Sign in at myaccount.google.com with your account.
  2. In the side menu, click Security.
  3. Look for the "How you sign in to Google" section and click 2-Step Verification.
  4. Click Get started and confirm your password when asked.
  5. Choose the method you want to use as the second step: you can start with your phone number and later add an authenticator app as an additional or primary method.
  6. Follow the on-screen instructions, enter the confirmation code you receive, and click Turn on.

The process is very similar on most services: Instagram, Facebook, Amazon, or your bank have this option within their "Security" or "Privacy and security" settings.

4. Why it's better to use an authenticator app instead of just SMS

Many services turn on SMS as the default method because it's the easiest to set up, but it's not the safest. Besides the risk of SIM swapping, SMS depends on having coverage: if you travel or lose signal, you can end up unable to receive the code right when you need it most.

An authenticator app, on the other hand, generates the code on the phone itself, without needing a connection or phone signal. If the service you use allows it, we recommend setting up an authenticator app as your main method and leaving SMS only as a backup option.

5. Keep your backup codes somewhere safe

When you turn on two-step verification, almost every service offers to download or write down a list of backup codes: one-time-use codes meant to get you into your account if at some point you don't have access to your usual method (for example, if you've lost your phone).

Keep these codes somewhere safe that only you control: a password manager, a printed sheet kept at home, or a digital safe. Avoid leaving them in an unprotected note on your phone, in an unencrypted email, or in a text document that's easily accessible on your computer. Each code can only be used once, so if you use them all up, you can generate a new list from the account's security settings.

6. What to do if you lose access to your second factor

If your phone is lost or stolen and it was the device where you received your codes, don't panic: follow these steps.

If you didn't save any backup codes, you'll have to go through the service's usual account recovery process (similar to recovering a forgotten password), providing as much information as possible to prove the account is yours. It can take a bit longer, which is why it's so important to save your backup codes from day one.

✔ With two-step verification turned on and your backup codes kept somewhere safe, your most important accounts stay protected even if your password ends up leaking.
Espacio publicitario (Google AdSense)

Frequently asked questions

Is two-step verification really necessary if I already have a strong password?

Yes. No matter how strong your password is, it could leak in a data breach at a service you use, or be stolen through phishing. Two-step verification adds an extra barrier that blocks access even if someone has your password.

What happens if I lose the phone where I receive verification codes?

You can use the backup codes generated when you turned on two-step verification to log in without the phone. If you didn't save them, you'll have to follow the service's account recovery process, providing as much information as possible to verify your identity.

Is it better to use SMS or an authenticator app for two-step verification?

The authenticator app is more secure. SMS codes can be intercepted or stolen through a fraudulent SIM duplicate, while authenticator apps generate the code directly on your phone without relying on the network.

You might also like

Have questions about this article?

Leave them in the comments and we'll help you out. To comment you need to sign up (with email, Google, or Facebook). Comments only load if you accept cookies.