Protect your accounts: passwords, passkeys and two-step sign-in
Phishing works because one stolen password opens an account. A few settings, done once, mean a stolen password is no longer enough.
The short version
- Use a password manager, so every account gets its own long password.
- Turn on passkeys or two-step sign-in, starting with your email account.
- Keep your recovery email and phone number up to date.
- Your email account is the key to all the others. Protect it first.
Do these in order
Start with your email account
Password resets for almost everything else go to your email. Whoever controls it can take over the rest.
Use a password manager
It creates and remembers a different long password for every site, so one leak does not unlock the others. It also refuses to fill your password on a fake site, which catches phishing.
Turn on passkeys where offered
A passkey replaces the password with your phone or computer's lock. It only works on the real site, so it cannot be phished.
Otherwise, turn on two-step sign-in
An authenticator app or a security key is best; a text message code is weaker but much better than nothing.
Check your recovery details
Make sure the recovery email and phone number are yours and current, and save your backup codes somewhere safe.
Review sessions and connected apps
Once in a while, sign out devices you do not recognise and remove apps you no longer use.
Check a link now, free
Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.
Questions people ask
- Is a password manager safe? It puts everything in one place.
- A reputable manager with a strong master password and two-step sign-in is far safer than reusing passwords, which is how most accounts are taken over.
- How do I know if my password has leaked?
- Most password managers and browsers warn you about passwords found in known breaches. Change any password they flag, starting with the ones you reused.
More guides
Fake sign-in pages for Microsoft 365, Outlook and Google are the most common phishing page. How they work, how to tell, and why two-step sign-in is not always enough.
Clicked a phishing link or typed your password into a fake page? The steps to take right now, depending on what happened, in the order that limits the damage.
A 30-second checklist for suspicious emails: the real sender, the pressure, the links, the attachments and the request. Plus what to do when you find one.