Protect your accounts: passwords, passkeys and two-step sign-in

Phishing works because one stolen password opens an account. A few settings, done once, mean a stolen password is no longer enough.

Updated 24 September 2026 · 5 min read

The short version

  • Use a password manager, so every account gets its own long password.
  • Turn on passkeys or two-step sign-in, starting with your email account.
  • Keep your recovery email and phone number up to date.
  • Your email account is the key to all the others. Protect it first.

Do these in order

  1. Start with your email account

    Password resets for almost everything else go to your email. Whoever controls it can take over the rest.

  2. Use a password manager

    It creates and remembers a different long password for every site, so one leak does not unlock the others. It also refuses to fill your password on a fake site, which catches phishing.

  3. Turn on passkeys where offered

    A passkey replaces the password with your phone or computer's lock. It only works on the real site, so it cannot be phished.

  4. Otherwise, turn on two-step sign-in

    An authenticator app or a security key is best; a text message code is weaker but much better than nothing.

  5. Check your recovery details

    Make sure the recovery email and phone number are yours and current, and save your backup codes somewhere safe.

  6. Review sessions and connected apps

    Once in a while, sign out devices you do not recognise and remove apps you no longer use.

The one rule that stops most scams

Never share a one-time code, and never approve a sign-in you did not start. Banks, support desks and delivery companies never need your code. Someone asking for it is trying to sign in as you right now.

Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.

Live product launcher
Paste a suspicious URL or domain, then continue in the live platform

Questions people ask

Is a password manager safe? It puts everything in one place.
A reputable manager with a strong master password and two-step sign-in is far safer than reusing passwords, which is how most accounts are taken over.
How do I know if my password has leaked?
Most password managers and browsers warn you about passwords found in known breaches. Change any password they flag, starting with the ones you reused.