Your password is just the beginning.
A practical routine for safer accounts, from your sign-in to your recovery options.
Protect your email first
Your main email account is often the recovery path for banking, shopping, and social accounts. Give it a unique password, review signed-in devices, and remove recovery addresses or phone numbers you no longer control. Review forwarding rules if you suspect compromise.
Enable a second layer
Multifactor authentication reduces reliance on a password alone. Prefer phishing-resistant options, such as supported passkeys or hardware security keys, when available. An authenticator app is useful where those options are not supported. A verification code can still be stolen by a convincing phishing page.
Understand passkeys
Passkeys use public-key cryptography and are bound to a website or application. They can make sign-in simpler and help resist phishing. Availability and recovery vary by provider and device ecosystem. Read the account’s recovery flow before relying on a new method exclusively.
Save recovery codes securely
Keep backup codes in a password manager or another protected location. Do not store the only copy on the device whose loss would lock you out. Treat recovery codes as credentials: anyone who obtains a valid code may bypass your usual second factor.
Keep devices and browsers current
Install security updates and review browser extensions. Extensions and malware can read or alter pages even when a website keeps secrets local. Avoid entering credentials on shared or untrusted devices, and lock your own device when you leave it.
Respond to a suspected breach
Use a trusted device to change exposed or reused passwords, revoke unfamiliar sessions, and check account recovery details. If your email was affected, prioritize it. Contact the service through a verified channel. Never send a password to anyone who claims they need it to investigate.