Account Security

Account Recovery Checklist: Prepare Before You Lose Access

Build a recovery plan for email, passkeys, MFA and lost devices before a forgotten password or stolen phone becomes a crisis.

Muhammad Azhar August 14, 2026 Reviewed August 14, 2026 3 min read

Account recovery is often weaker than the normal login. A strong password and passkey offer limited protection if an old phone number or unprotected recovery inbox can reset everything. Review recovery while you still have access.

Map the dependency chain

Write down which email address and phone number recover each important account. Then check what protects those recovery channels. If five services depend on one inbox, that inbox is a security priority.

Recovery checklist

  • Remove phone numbers and email addresses you no longer control.
  • Save fresh backup codes outside the account and everyday device.
  • Register a second passkey or hardware key where supported.
  • Review trusted devices and sign out abandoned hardware.
  • Confirm the legal name and billing information used for support verification.
  • Record official support URLs; search ads can impersonate support during a crisis.

Test without creating a lockout

Open a private window or second trusted device and confirm that the backup method reaches the correct account. Do not remove the existing method until the replacement works. Never publish backup codes in screenshots or store them in the same email they recover.

Plan for a stolen phone

Know how to reach the platform's lost-device service, the mobile carrier and the password vault from another device. Add a carrier account PIN and keep the device serial number where it can be retrieved without the phone.

After any recovery event

Review sessions, forwarding rules, connected applications, MFA methods and recent security activity. Recovery restores access; it does not prove that an intruder left no persistence behind.

A good recovery plan is deliberately redundant. Two independent credentials, current contact details and offline recovery material are easier to maintain than an improvised identity-verification battle.

Recovery channels are privileged credentials

An old phone number, forgotten secondary inbox or former employee address can become the easiest takeover path. Review them at least twice a year and immediately after changing carriers, employers or devices. Remove options you cannot actively test.

Document the order of operations

For a personal account, keep the provider's official recovery URL, offline codes and proof-of-ownership requirements. For a business, document who can authorize a reset, how identity is checked, how the event is logged and how access is removed after staff departure. Do not let an urgent caller redefine the process.

A good test is recovery without the everyday phone. If the only backup is an SMS sent to that device, the account has convenience, not resilience.

Sources and further reading

Use the right privacy tool for the task

A browser proxy changes the network path for one session. Review the Privacy Policy and use a trusted direct connection for sensitive accounts.