Lesson

Account Recovery

The final link in account security is preparing for the day you are locked out: recovery email, phone number and backup codes. This lesson teaches you to build your recovery chain before you lose access — and to keep it current.

Foundation · 11 min

In this lesson you will learn

  • Know the ways account access can be lost
  • Explain the recovery chain concept and the weak-link risk
  • Know the role of backup codes and how to store them properly
  • Audit and update the recovery details of your own accounts

The ways you get locked out

Account access is lost in more ways than you might think: the password is forgotten; the phone is lost or stolen (and the two-factor codes go with it); an old phone number is cancelled but stays registered on accounts; a recovery email untouched for years gets closed; or the service locks the account after an attack. The common thread: at none of these moments do you still have the chance to prepare. The preparation was either done in advance or not at all. This lesson is the lesson of that "in advance".

The recovery chain and the weak link

Your accounts are tied to each other by recovery links: your social media account recovers through your email; your email perhaps recovers through an older email or your phone number. This is a chain, and it cuts both ways. First: the account at the centre of the chain — usually your main email — is the one that must be guarded most tightly; whoever reaches it reaches everything on the chain. Second: a forgotten weak link — an old email address you can no longer access but which is still registered as a recovery address — can both lock you out and open a door for whoever takes over that old account. Reviewing the chain now and then is therefore a security operation, not bureaucracy.

Backup codes: the last key

When you enable two-factor authentication, most services hand you single-use backup codes. These codes are the last way into the account when your phone is lost or your number has changed; their importance appears exactly when everything else has gone wrong. Two rules apply. Store them: put the codes in your password manager's notes or in a safe physical place at home; do not skip this with a "surely I'll never need them". Keep them reachable: keeping the only copy of the codes on the very phone whose loss would cause the problem is putting the key behind the locked door. Knowing where the code list is also counts as storing it; choose a place that is safe but memorable.

Some services also offer, instead of or alongside codes, a trusted second device or a printable recovery key; whatever options are offered, set up at least one.

The annual recovery check-up

Recovery details are not set-and-forget; life changes and the details go stale. A simple maintenance routine suffices: once a year (in the same month each year, say) open the security pages of your important accounts and check four things: is the registered recovery email an address you can still access, is the phone number current, are the backup codes in place and unused, and does the list of signed-in devices contain anything you do not recognise? The tour takes a few minutes per account and saves hours — sometimes weeks — on the worst day. Doing this tour once before moving on to the programme assessment is the best possible way to finish.

Common mistake: Deferring recovery to the crisis

Recovery details are typically thought about at two moments: when opening the account (hastily, at random) and when access is lost (in panic, too late). Both are bad times. Someone who forgets to update an old number on their accounts may never realise that, once the number is reassigned, their recovery SMS messages are going to a stranger. The right time for recovery preparation is an uneventful day — like today. A ten-minute currency tour is the crisis day's most valuable investment.

Today's practice

Open your main email account's security page today and run the four checks: is the recovery email reachable, is the phone number current, are your backup codes somewhere safe, are the active sessions familiar? Fix every gap you find immediately. Then set a reminder on your phone for one year from now: "recovery check-up".

Summary

  • Access loss comes by many roads: forgotten passwords, lost phones, stale numbers and emails
  • Accounts form a chain of recovery links; the central main email must be guarded most tightly
  • A forgotten weak link both locks you out and can open a door to an attacker
  • Backup codes are the last key: safe, reachable, and stored independently of the phone
  • An annual recovery check-up — email, number, codes, sessions — saves hours in a crisis

Check your understanding

Questions and answer order are shuffled on every attempt. Results stay in your browser.

First published: 2026-08-12Last reviewed: 2026-08-12Editorial status: working editionReport an error